CVE-2021-41057

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
wibucodemeter_runtime
𝑥
< 7.30a
siemenspss_e
34.0.0 ≤
𝑥
< 34.9.1
siemenspss_e
35.0.0 ≤
𝑥
< 35.3.2
siemenspss_odms
𝑥
< 12.2.6.1
siemenssicam_230
𝑥
< 8.0
siemenssimatic_information_server
𝑥
< 2019
siemenssimatic_pcs_neo
*
siemenssimatic_process_historian
𝑥
≤ 2019
siemenssimatic_wincc_oa
𝑥
≤ 3.18
siemenssimit
𝑥
≤ 10.0
𝑥
= Vulnerable software versions