CVE-2021-37181
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.
Se ha identificado una vulnerabilidad en Cerberus DMS V4.0 (Todas las versiones), Cerberus DMS versión V4.1 (Todas las versiones), Cerberus DMS versión V4.2 (Todas las versiones), Cerberus DMS versión V5.0 (Todas las versiones anteriores a v5.0 QU1), Desigo CC Compact versión V4.0 (Todas las versiones), Desigo CC Compact versión V4. 1 (Todas las versiones), Desigo CC Compact versión V4.2 (Todas las versiones), Desigo CC Compact versión V5.0 (Todas las versiones anteriores a V5.0 QU1), Desigo CC versión V4.0 (Todas las versiones), Desigo CC versión V4.1 (Todas las versiones), Desigo CC versión V4.2 (Todas las versiones), Desigo CC versión V5.0 (Todas las versiones anteriores a V5.0 QU1). La aplicación deserializa datos no confiables sin suficientes comprobaciones, que podría resultar en una deserialización arbitraria. Esto podría permitir a un atacante no autenticado ejecutar código en el sistema afectado. El componente CCOM communication usado para la conectividad de los clientes Windows App / Click-Once e IE Web / XBAP están afectados por la vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-21 CVE Reserved
- 2021-09-14 CVE Published
- 2024-08-04 CVE Updated
- 2024-10-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-453715.pdf | 2021-09-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Cerberus Dms Search vendor "Siemens" for product "Cerberus Dms" | 4.0 Search vendor "Siemens" for product "Cerberus Dms" and version "4.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Cerberus Dms Search vendor "Siemens" for product "Cerberus Dms" | 4.1 Search vendor "Siemens" for product "Cerberus Dms" and version "4.1" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Cerberus Dms Search vendor "Siemens" for product "Cerberus Dms" | 4.2 Search vendor "Siemens" for product "Cerberus Dms" and version "4.2" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Cerberus Dms Search vendor "Siemens" for product "Cerberus Dms" | 5.0 Search vendor "Siemens" for product "Cerberus Dms" and version "5.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Search vendor "Siemens" for product "Desigo Cc" | 4.0 Search vendor "Siemens" for product "Desigo Cc" and version "4.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Search vendor "Siemens" for product "Desigo Cc" | 4.1 Search vendor "Siemens" for product "Desigo Cc" and version "4.1" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Search vendor "Siemens" for product "Desigo Cc" | 4.2 Search vendor "Siemens" for product "Desigo Cc" and version "4.2" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Search vendor "Siemens" for product "Desigo Cc" | 5.0 Search vendor "Siemens" for product "Desigo Cc" and version "5.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Compact Search vendor "Siemens" for product "Desigo Cc Compact" | 4.0 Search vendor "Siemens" for product "Desigo Cc Compact" and version "4.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Compact Search vendor "Siemens" for product "Desigo Cc Compact" | 4.1 Search vendor "Siemens" for product "Desigo Cc Compact" and version "4.1" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Compact Search vendor "Siemens" for product "Desigo Cc Compact" | 4.2 Search vendor "Siemens" for product "Desigo Cc Compact" and version "4.2" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Desigo Cc Compact Search vendor "Siemens" for product "Desigo Cc Compact" | 5.0 Search vendor "Siemens" for product "Desigo Cc Compact" and version "5.0" | - |
Affected
|