A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
2021-06-16T12:15:12.037
2024-11-21T05:45:54.840
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | wibu | codemeter | ≤ 7.21a | Yes |
Application | siemens | pss_cape | - | Yes |
Operating System | siemens | sicam_230_firmware | * | Yes |
Hardware | siemens | sicam_230 | - | No |
Application | siemens | simatic_information_server | 2019 | Yes |
Application | siemens | simatic_information_server | 2020 | Yes |
Application | siemens | simatic_pcs_neo | < 3.1 | Yes |
Application | siemens | simatic_wincc_oa | 3.17 | Yes |
Application | siemens | simatic_wincc_oa | 3.18 | Yes |
Application | siemens | simit_simulation_platform | < 10.3 | Yes |
Application | siemens | simit_simulation_platform | 10.3 | Yes |
Application | siemens | sinec_infrastructure_network_services | < 1.0.1.1 | Yes |
Application | siemens | sinec_infrastructure_network_services | 1.0.1 | Yes |
Application | siemens | sinema_remote_connect_server | < 3.0 | Yes |
Application | siemens | sinema_remote_connect_server | 3.0 | Yes |
Application | siemens | sinema_remote_connect_server | 3.0 | Yes |
Hardware | siemens | simatic_process_historian | < 2020 | Yes |
Hardware | siemens | simatic_process_historian | 2020 | Yes |