CVE-2021-20093: Critical severity wibu-systems ag codemeter runtime vulnerability
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20093?
CVE-2021-20093 is a buffer over-read vulnerability in Wibu-Systems CodeMeter versions < 7.21a.
How can an attacker exploit CVE-2021-20093?
An unauthenticated remote attacker can exploit CVE-2021-20093 to disclose heap memory contents or crash the CodeMeter Runtime Server.
Which software versions are affected by CVE-2021-20093?
Wibu-Systems CodeMeter versions < 7.21a, Siemens Pss Cape, Siemens Sicam 230 Firmware, Siemens Simatic Information Server 2019-sp1 and 2020, Siemens Simatic Pcs Neo, Siemens Simatic Wincc Oa 3.17 and 3.18, Siemens Simit Simulation Platform 10.0 to 10.3, Siemens Sinec Infrastructure Network Services up to 1.0.1.1, Siemens Sinema Remote Connect Server up to 3.0 and 3.0-sp1, and Siemens Simatic Process Historian 2019 to 2020 are affected by CVE-2021-20093.
What is the severity of CVE-2021-20093?
CVE-2021-20093 has a severity rating of 9.1 (Critical).
Where can I find more information about CVE-2021-20093?
You can find more information about CVE-2021-20093 at the following references: [Link 1](https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-01.pdf), [Link 2](https://cert-portal.siemens.com/productcert/pdf/ssa-675303.pdf), [Link 3](https://us-cert.cisa.gov/ics/advisories/icsa-21-210-02).