CVE-2021-41057: High severity wibu codemeter runtime vulnerability
Published Nov 14, 2021
·Updated
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Affected Software
14 affected components
Wibu CodeMeter Runtime<7.30a
Microsoft Windows
Siemens Pss Cape=14
Siemens Pss E>=34.0.0<34.9.1
Siemens Pss E>=35.0.0<35.3.2
Siemens Pss Odms<12.2.6.1
Siemens Sicam 230<8.0
Siemens Simatic Information Server<2019
Siemens Simatic Information Server=2019
Siemens Simatic Information Server=2019-sp1
Siemens Simatic Pcs Neo
Siemens Simatic Process Historian<=2019
Siemens Simatic Wincc Oa<=3.18
Siemens Simit<=10.0
Event History
Nov 14, 2021
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
Description
Frequently Asked Questions
1
What is CVE-2021-41057?
CVE-2021-41057 is a vulnerability in WIBU CodeMeter Runtime before 7.30a that allows an attacker to overwrite a linked file without checking permissions.
2
What software is affected by CVE-2021-41057?
WIBU CodeMeter Runtime before 7.30a is affected by CVE-2021-41057.
3
How severe is CVE-2021-41057?
CVE-2021-41057 has a severity rating of 7.1 (high).
4
How can I fix CVE-2021-41057?
To fix CVE-2021-41057, update WIBU CodeMeter Runtime to version 7.30a or later.
5
Where can I find more information about CVE-2021-41057?
More information about CVE-2021-41057 can be found in the following references: [1] WIBU CodeMeter Runtime Advisory, [2] Siemens ProductCERT Advisory, [3] WIBU Security Advisories.