VDB

CVE-2021-37181

CVE-2021-37181 PUBLISHED CVSS 10 CRITICAL

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.

EPSS 1.10% · 78.3th percentile

Risk Scores

CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
1.10%
78.3th percentile

Affected Products

VendorProductVersions
SiemensCerberus DMS V4.1All versions
SiemensDesigo CC Compact V4.2All versions
siemenscerberus_dms4.1, 5.0, 4.2
SiemensDesigo CC Compact V5.0All versions < V5.0 QU1
SiemensDesigo CC V4.1All versions
SiemensCerberus DMS V4.2All versions
SiemensDesigo CC Compact V4.0All versions
SiemensCerberus DMS V4.0All versions
SiemensDesigo CC V4.0All versions
SiemensDesigo CC V5.0All versions < V5.0 QU1
SiemensDesigo CC Compact V4.1*
SiemensCerberus DMS V5.0*
siemensdesigo_cc4.2, 5.0, 4.0
SiemensDesigo CC V4.2All versions
siemensdesigo_cc_compact5.0, 4.2, 4.0

Timeline

  • Apr 13, 2021 CVE Published
  • Sep 15, 2021 EPSS Score
  • Nov 11, 2021 EPSS Score
  • Jan 8, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 6, 2022 EPSS Score
  • May 3, 2022 EPSS Score
  • Jun 29, 2022 EPSS Score
  • Aug 26, 2022 EPSS Score
  • Oct 23, 2022 EPSS Score
  • Feb 15, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›