IT

Tracker / CVE-2021-41057

CVE-2021-41057

High 7.1

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

Affected products and versions

siemens pss_cape
siemens pss_e · 34.0.0 → 34.9.1
siemens pss_e · 35.0.0 → 35.3.2
siemens pss_odms · … → 12.2.6.1
siemens sicam_230 · … → 8.0
siemens simatic_information_server
siemens simatic_information_server · … → 2019
siemens simatic_pcs_neo
siemens simatic_process_historian · … → 2019
siemens simatic_wincc_oa · … → 3.18
siemens simit · … → 10.0
wibu codemeter_runtime · … → 7.30a

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References