CVE detail
CVE-2023-46601 — CVE-2023-46601
Published 2023-11-14 · Modified 2026-06-17 · Vendor siemens · Product comos · Source nvd
CRITICAL
severity
CVSS-derived band
0.0052
EPSS probability
exploitation probability, 30d
41.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References