CVE-2021-41057
14.11.2021, 21:15
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Vendor | Product | Version |
---|---|---|
wibu | codemeter_runtime | 𝑥 < 7.30a |
siemens | pss_e | 34.0.0 ≤ 𝑥 < 34.9.1 |
siemens | pss_e | 35.0.0 ≤ 𝑥 < 35.3.2 |
siemens | pss_odms | 𝑥 < 12.2.6.1 |
siemens | sicam_230 | 𝑥 < 8.0 |
siemens | simatic_information_server | 𝑥 < 2019 |
siemens | simatic_pcs_neo | * |
siemens | simatic_process_historian | 𝑥 ≤ 2019 |
siemens | simatic_wincc_oa | 𝑥 ≤ 3.18 |
siemens | simit | 𝑥 ≤ 10.0 |
𝑥
= Vulnerable software versions
References