CVE Database
/

CVE-2021-37181

Back to search

CVE-2021-37181

Published: Sep 14, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.

VendorProductVersions

Siemens

Cerberus DMS V4.0

affected
All versions

Siemens

Cerberus DMS V4.1

affected
All versions

Siemens

Cerberus DMS V4.2

affected
All versions

Siemens

Cerberus DMS V5.0

affected
All versions < v5.0 QU1

Siemens

Desigo CC Compact V4.0

affected
All versions

Siemens

Desigo CC Compact V4.1

affected
All versions

Siemens

Desigo CC Compact V4.2

affected
All versions

Siemens

Desigo CC Compact V5.0

affected
All versions < V5.0 QU1

Siemens

Desigo CC V4.0

affected
All versions

Siemens

Desigo CC V4.1

affected
All versions

Siemens

Desigo CC V4.2

affected
All versions

Siemens

Desigo CC V5.0

affected
All versions < V5.0 QU1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now