CVE-2021-41057
Published Nov 14, 2021In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Vendor/product archive
2 CVEs tagged to siemens / simatic_information_server — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or c…