Lucene search

K
nvd[email protected]NVD:CVE-2021-41057
HistoryNov 14, 2021 - 9:15 p.m.

CVE-2021-41057

2021-11-1421:15:07
CWE-59
web.nvd.nist.gov
6
wibu codemeter
runtime
symbolic links
permissions
vulnerability

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS

0

Percentile

12.6%

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

Affected configurations

Nvd
Node
wibucodemeter_runtimeRange<7.30a
AND
microsoftwindowsMatch-
Node
siemenspss_capeMatch14
OR
siemenspss_eRange34.0.034.9.1
OR
siemenspss_eRange35.0.035.3.2
OR
siemenspss_odmsRange<12.2.6.1
OR
siemenssicam_230Range<8.0
OR
siemenssimatic_information_serverRange<2019
OR
siemenssimatic_information_serverMatch2019-
OR
siemenssimatic_information_serverMatch2019sp1
OR
siemenssimatic_pcs_neo
OR
siemenssimatic_process_historianRange2019
OR
siemenssimatic_wincc_oaRange3.18
OR
siemenssimitRange10.0
VendorProductVersionCPE
wibucodemeter_runtime*cpe:2.3:a:wibu:codemeter_runtime:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
siemenspss_cape14cpe:2.3:a:siemens:pss_cape:14:*:*:*:*:*:*:*
siemenspss_e*cpe:2.3:a:siemens:pss_e:*:*:*:*:*:*:*:*
siemenspss_odms*cpe:2.3:a:siemens:pss_odms:*:*:*:*:*:*:*:*
siemenssicam_230*cpe:2.3:a:siemens:sicam_230:*:*:*:*:*:*:*:*
siemenssimatic_information_server*cpe:2.3:a:siemens:simatic_information_server:*:*:*:*:*:*:*:*
siemenssimatic_information_server2019cpe:2.3:a:siemens:simatic_information_server:2019:-:*:*:*:*:*:*
siemenssimatic_information_server2019cpe:2.3:a:siemens:simatic_information_server:2019:sp1:*:*:*:*:*:*
siemenssimatic_pcs_neo*cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2021-41057