CVE-2021-20093 is a critical buffer over-read vulnerability affecting Wibu-Systems CodeMeter versions prior to 7.21a, impacting products from vendors like Siemens. This flaw allows an unauthenticated remote attacker to disclose heap memory contents or crash the CodeMeter Runtime Server with low attack complexity. While not listed on CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.21aCPE matchmatch criteria | cpe:2.3:a:wibu:codemeter:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:siemens:pss_cape:-:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:sicam_230_firmware:*:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_information_server:2019:sp1:*:*:*:*:*:* | ||
2020CPE matchmatch criteria | cpe:2.3:a:siemens:simatic_information_server:2020:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Vulnerability in FactoryTalk Activation Manager