// For flags

CVE-2021-37181

 

Severity Score

10.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.

Se ha identificado una vulnerabilidad en Cerberus DMS V4.0 (Todas las versiones), Cerberus DMS versión V4.1 (Todas las versiones), Cerberus DMS versión V4.2 (Todas las versiones), Cerberus DMS versión V5.0 (Todas las versiones anteriores a v5.0 QU1), Desigo CC Compact versión V4.0 (Todas las versiones), Desigo CC Compact versión V4. 1 (Todas las versiones), Desigo CC Compact versión V4.2 (Todas las versiones), Desigo CC Compact versión V5.0 (Todas las versiones anteriores a V5.0 QU1), Desigo CC versión V4.0 (Todas las versiones), Desigo CC versión V4.1 (Todas las versiones), Desigo CC versión V4.2 (Todas las versiones), Desigo CC versión V5.0 (Todas las versiones anteriores a V5.0 QU1). La aplicación deserializa datos no confiables sin suficientes comprobaciones, que podría resultar en una deserialización arbitraria. Esto podría permitir a un atacante no autenticado ejecutar código en el sistema afectado. El componente CCOM communication usado para la conectividad de los clientes Windows App / Click-Once e IE Web / XBAP están afectados por la vulnerabilidad

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-21 CVE Reserved
  • 2021-09-14 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-20 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Cerberus Dms
Search vendor "Siemens" for product "Cerberus Dms"
4.0
Search vendor "Siemens" for product "Cerberus Dms" and version "4.0"
-
Affected
Siemens
Search vendor "Siemens"
Cerberus Dms
Search vendor "Siemens" for product "Cerberus Dms"
4.1
Search vendor "Siemens" for product "Cerberus Dms" and version "4.1"
-
Affected
Siemens
Search vendor "Siemens"
Cerberus Dms
Search vendor "Siemens" for product "Cerberus Dms"
4.2
Search vendor "Siemens" for product "Cerberus Dms" and version "4.2"
-
Affected
Siemens
Search vendor "Siemens"
Cerberus Dms
Search vendor "Siemens" for product "Cerberus Dms"
5.0
Search vendor "Siemens" for product "Cerberus Dms" and version "5.0"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc
Search vendor "Siemens" for product "Desigo Cc"
4.0
Search vendor "Siemens" for product "Desigo Cc" and version "4.0"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc
Search vendor "Siemens" for product "Desigo Cc"
4.1
Search vendor "Siemens" for product "Desigo Cc" and version "4.1"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc
Search vendor "Siemens" for product "Desigo Cc"
4.2
Search vendor "Siemens" for product "Desigo Cc" and version "4.2"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc
Search vendor "Siemens" for product "Desigo Cc"
5.0
Search vendor "Siemens" for product "Desigo Cc" and version "5.0"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc Compact
Search vendor "Siemens" for product "Desigo Cc Compact"
4.0
Search vendor "Siemens" for product "Desigo Cc Compact" and version "4.0"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc Compact
Search vendor "Siemens" for product "Desigo Cc Compact"
4.1
Search vendor "Siemens" for product "Desigo Cc Compact" and version "4.1"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc Compact
Search vendor "Siemens" for product "Desigo Cc Compact"
4.2
Search vendor "Siemens" for product "Desigo Cc Compact" and version "4.2"
-
Affected
Siemens
Search vendor "Siemens"
Desigo Cc Compact
Search vendor "Siemens" for product "Desigo Cc Compact"
5.0
Search vendor "Siemens" for product "Desigo Cc Compact" and version "5.0"
-
Affected