Vulnerability Details CVE-2021-41057
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.7%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 3.6
Products affected by CVE-2021-41057
-
cpe:2.3:a:siemens:pss_cape:14
-
cpe:2.3:a:siemens:pss_e:*
-
cpe:2.3:a:siemens:pss_odms:*
-
cpe:2.3:a:siemens:sicam_230:*
-
cpe:2.3:a:siemens:simatic_information_server:*
-
cpe:2.3:a:siemens:simatic_information_server:2019
-
cpe:2.3:a:siemens:simatic_pcs_neo:-
-
cpe:2.3:a:siemens:simatic_pcs_neo:3.0
-
cpe:2.3:a:siemens:simatic_pcs_neo:3.1
-
cpe:2.3:a:siemens:simatic_pcs_neo:4.0
-
cpe:2.3:a:siemens:simatic_pcs_neo:4.1
-
cpe:2.3:a:siemens:simatic_process_historian:*
-
cpe:2.3:a:siemens:simatic_wincc_oa:3.15
-
cpe:2.3:a:siemens:simatic_wincc_oa:3.15-p018
-
cpe:2.3:a:siemens:simatic_wincc_oa:3.16
-
cpe:2.3:a:siemens:simatic_wincc_oa:3.17
-
cpe:2.3:a:siemens:simatic_wincc_oa:3.18
-
cpe:2.3:a:siemens:simit:9.0
-
cpe:2.3:a:wibu:codemeter_runtime:5.10c
-
cpe:2.3:o:microsoft:windows:-