First published: Sun Nov 14 2021(Updated: )
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wibu CodeMeter Runtime | <7.30a | |
Microsoft Windows | ||
Siemens Pss Cape | =14 | |
Siemens Pss E | >=34.0.0<34.9.1 | |
Siemens Pss E | >=35.0.0<35.3.2 | |
Siemens Pss Odms | <12.2.6.1 | |
Siemens Sicam 230 | <8.0 | |
Siemens Simatic Information Server | <2019 | |
Siemens Simatic Information Server | =2019 | |
Siemens Simatic Information Server | =2019-sp1 | |
Siemens Simatic Pcs Neo | ||
Siemens Simatic Process Historian | <=2019 | |
Siemens Simatic Wincc Oa | <=3.18 | |
Siemens Simit | <=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41057 is a vulnerability in WIBU CodeMeter Runtime before 7.30a that allows an attacker to overwrite a linked file without checking permissions.
WIBU CodeMeter Runtime before 7.30a is affected by CVE-2021-41057.
CVE-2021-41057 has a severity rating of 7.1 (high).
To fix CVE-2021-41057, update WIBU CodeMeter Runtime to version 7.30a or later.
More information about CVE-2021-41057 can be found in the following references: [1] WIBU CodeMeter Runtime Advisory, [2] Siemens ProductCERT Advisory, [3] WIBU Security Advisories.