← Back

CVE-2021-41057

nvd nist
Published: Nov 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

Affected (13)

1 product
Codemeter Runtime
9 products
Pss Cape
Pss E
Pss Odms
Sicam 230
Simatic Information Server
Simatic Pcs Neo
Simatic Process Historian
Simatic Wincc Oa
Simit
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.30a
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Version 14
Siemens
From 34.0.0 to 34.9.1
From 35.0.0 to 35.3.2
Before 12.2.6.1
Before 8.0
Siemens
Before 2019
Version 2019
Version 2019 sp1
All versions
Up to 2019
Up to 3.18
Up to 10.0

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.