CVE-2021-20094 is a denial of service vulnerability affecting Wibu-Systems CodeMeter versions prior to 7.21a, impacting various Siemens products that utilize CodeMeter. An unauthenticated remote attacker can exploit this with low attack complexity to crash the CodeMeter Runtime Server, resulting in high availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.21aCPE matchmatch criteria | cpe:2.3:a:wibu:codemeter:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:siemens:pss_cape:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:siemens:sicam_230_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Multiple Vulnerabilities in Wibu-Systems CodeMeter
Jun 15, 2021Vulnerability in FactoryTalk Activation Manager