CVE-2021-20093

A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
tenableCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
wibucodemeter
𝑥
≤ 7.21a
siemenspss_cape
-
siemenssicam_230_firmware
*
siemenssimatic_pcs_neo
𝑥
< 3.1
siemenssimatic_wincc_oa
3.17
siemenssimatic_wincc_oa
3.18
siemenssimit_simulation_platform
10.0 ≤
𝑥
< 10.3
siemenssimit_simulation_platform
10.3
siemenssinec_infrastructure_network_services
𝑥
< 1.0.1.1
siemenssinec_infrastructure_network_services
1.0.1
siemenssinema_remote_connect_server
𝑥
< 3.0
siemenssinema_remote_connect_server
3.0
siemenssinema_remote_connect_server
3.0:sp1
siemenssimatic_process_historian
2019 ≤
𝑥
< 2020
𝑥
= Vulnerable software versions