CVE-2021-41057

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
14/11/2021
Last modified:
17/11/2021

Description

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wibu:codemeter_runtime:*:*:*:*:*:*:*:* 7.30a (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:pss_cape:14:*:*:*:*:*:*:*
cpe:2.3:a:siemens:pss_e:*:*:*:*:*:*:*:* 34.0.0 (including) 34.9.1 (excluding)
cpe:2.3:a:siemens:pss_e:*:*:*:*:*:*:*:* 35.0.0 (including) 35.3.2 (excluding)
cpe:2.3:a:siemens:pss_odms:*:*:*:*:*:*:*:* 12.2.6.1 (excluding)
cpe:2.3:a:siemens:sicam_230:*:*:*:*:*:*:*:* 8.0 (excluding)
cpe:2.3:a:siemens:simatic_information_server:*:*:*:*:*:*:*:* 2019 (excluding)
cpe:2.3:a:siemens:simatic_information_server:2019:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_information_server:2019:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_process_historian:*:*:*:*:*:*:*:* 2019 (including)
cpe:2.3:a:siemens:simatic_wincc_oa:*:*:*:*:*:*:*:* 3.18 (including)
cpe:2.3:a:siemens:simit:*:*:*:*:*:*:*:* 10.0 (including)