First published: Wed Jun 16 2021(Updated: )
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wibu Codemeter | <=7.21a | |
Siemens Pss Cape | ||
Siemens Sicam 230 Firmware | ||
Siemens Sicam 230 | ||
Siemens Simatic Information Server | =2019-sp1 | |
Siemens Simatic Information Server | =2020 | |
Siemens Simatic Pcs Neo | <3.1 | |
Siemens Simatic Wincc Oa | =3.17 | |
Siemens Simatic Wincc Oa | =3.18 | |
Siemens Simit Simulation Platform | >=10.0<10.3 | |
Siemens Simit Simulation Platform | =10.3 | |
Siemens Sinec Infrastructure Network Services | <1.0.1.1 | |
Siemens Sinec Infrastructure Network Services | =1.0.1 | |
Siemens SINEMA Remote Connect Server | <3.0 | |
Siemens SINEMA Remote Connect Server | =3.0 | |
Siemens SINEMA Remote Connect Server | =3.0-sp1 | |
Siemens Simatic Process Historian | >=2019<2020 | |
Siemens Simatic Process Historian | =2020 | |
Wibu-Systems AG CodeMeter Runtimea | <7.21 | 7.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter versions < 7.21a.
An unauthenticated remote attacker can exploit CVE-2021-20093 to disclose heap memory contents or crash the CodeMeter Runtime Server.
Wibu-Systems CodeMeter versions < 7.21a, Siemens Pss Cape, Siemens Sicam 230 Firmware, Siemens Simatic Information Server 2019-sp1 and 2020, Siemens Simatic Pcs Neo, Siemens Simatic Wincc Oa 3.17 and 3.18, Siemens Simit Simulation Platform 10.0 to 10.3, Siemens Sinec Infrastructure Network Services up to 1.0.1.1, Siemens Sinema Remote Connect Server up to 3.0 and 3.0-sp1, and Siemens Simatic Process Historian 2019 to 2020 are affected by CVE-2021-20093.
CVE-2021-20093 has a severity rating of 9.1 (Critical).
You can find more information about CVE-2021-20093 at the following references: [Link 1](https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-01.pdf), [Link 2](https://cert-portal.siemens.com/productcert/pdf/ssa-675303.pdf), [Link 3](https://us-cert.cisa.gov/ics/advisories/icsa-21-210-02).