First published: Wed Jun 16 2021(Updated: )
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wibu-Systems AG CodeMeter Runtimea | <7.21 | 7.21 |
Wibu CodeMeter | <=7.21a | |
siemens pss cape | ||
Siemens SICAM 230 | ||
Siemens SICAM 230 Firmware | ||
Siemens SIMATIC Information Server 2022 | =2019-sp1 | |
Siemens SIMATIC Information Server 2022 | =2020 | |
Siemens SIMATIC PCS neo V4.0 | <3.1 | |
Siemens SIMATIC WinCC OA V3.18 | =3.17 | |
Siemens SIMATIC WinCC OA V3.18 | =3.18 | |
Siemens SIMIT | >=10.0<10.3 | |
Siemens SIMIT | =10.3 | |
siemens sinec infrastructure network services | <1.0.1.1 | |
siemens sinec infrastructure network services | =1.0.1 | |
Siemens SINEMA Remote Connect | <3.0 | |
Siemens SINEMA Remote Connect | =3.0 | |
Siemens SINEMA Remote Connect | =3.0-sp1 | |
Siemens SIMATIC Process Historian | >=2019<2020 | |
Siemens SIMATIC Process Historian | =2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter versions < 7.21a.
An unauthenticated remote attacker can exploit CVE-2021-20093 to disclose heap memory contents or crash the CodeMeter Runtime Server.
Wibu-Systems CodeMeter versions < 7.21a, Siemens Pss Cape, Siemens Sicam 230 Firmware, Siemens Simatic Information Server 2019-sp1 and 2020, Siemens Simatic Pcs Neo, Siemens Simatic Wincc Oa 3.17 and 3.18, Siemens Simit Simulation Platform 10.0 to 10.3, Siemens Sinec Infrastructure Network Services up to 1.0.1.1, Siemens Sinema Remote Connect Server up to 3.0 and 3.0-sp1, and Siemens Simatic Process Historian 2019 to 2020 are affected by CVE-2021-20093.
CVE-2021-20093 has a severity rating of 9.1 (Critical).
You can find more information about CVE-2021-20093 at the following references: [Link 1](https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-01.pdf), [Link 2](https://cert-portal.siemens.com/productcert/pdf/ssa-675303.pdf), [Link 3](https://us-cert.cisa.gov/ics/advisories/icsa-21-210-02).