CRITICAL🇵🇱 Wersja polska

CVE-2021-37181

CVSS 10.0v3.1pub. 2021-09-14upd. 2024-11-21

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Siemens Cerberus Dms

    APP
    Siemens
    4.04.14.25.0
  • Siemens Desigo Cc

    APP
    Siemens
    4.04.14.25.0
  • Siemens Desigo Cc Compact

    APP
    Siemens
    4.04.14.25.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDeserialization
CWE
References

Related vulnerabilities

CVE-2022-33139CRITICAL9.8PL ✓same product

Siemens Cerberus/Desigo/WinCC OA – ominięcie uwierzytelnienia (Auth Bypass)

CVE-2021-31891CRITICAL10.0PL ✓same product

Command Injection w modułach OIS produktów Siemens — RCE z uprawnieniami root

CVE-2026-0300CRITICAL9.3⚠ KEVPL ✓same vendor

Buffer overflow RCE z uprawnieniami root w PAN-OS Captive Portal

CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same vendor

Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach

CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same vendor

Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML