// For flags

CVE-2021-20093

 

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.

Se presenta una vulnerabilidad de lectura excesiva del bĂșfer en Wibu-Systems CodeMeter versiones anteriores a 7.21a. Un atacante remoto no autenticado puede explotar este problema para revelar el contenido de la memoria de la pila o bloquear el CodeMeter Runtime Server

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-06-16 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-10-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-125: Out-of-bounds Read
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Sicam 230 Firmware
Search vendor "Siemens" for product "Sicam 230 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Sicam 230
Search vendor "Siemens" for product "Sicam 230"
--
Safe
Wibu
Search vendor "Wibu"
Codemeter
Search vendor "Wibu" for product "Codemeter"
<= 7.21a
Search vendor "Wibu" for product "Codemeter" and version " <= 7.21a"
-
Affected
Siemens
Search vendor "Siemens"
Pss Cape
Search vendor "Siemens" for product "Pss Cape"
--
Affected
Siemens
Search vendor "Siemens"
Simatic Information Server
Search vendor "Siemens" for product "Simatic Information Server"
2019
Search vendor "Siemens" for product "Simatic Information Server" and version "2019"
sp1
Affected
Siemens
Search vendor "Siemens"
Simatic Information Server
Search vendor "Siemens" for product "Simatic Information Server"
2020
Search vendor "Siemens" for product "Simatic Information Server" and version "2020"
-
Affected
Siemens
Search vendor "Siemens"
Simatic Pcs Neo
Search vendor "Siemens" for product "Simatic Pcs Neo"
< 3.1
Search vendor "Siemens" for product "Simatic Pcs Neo" and version " < 3.1"
-
Affected
Siemens
Search vendor "Siemens"
Simatic Wincc Oa
Search vendor "Siemens" for product "Simatic Wincc Oa"
3.17
Search vendor "Siemens" for product "Simatic Wincc Oa" and version "3.17"
-
Affected
Siemens
Search vendor "Siemens"
Simatic Wincc Oa
Search vendor "Siemens" for product "Simatic Wincc Oa"
3.18
Search vendor "Siemens" for product "Simatic Wincc Oa" and version "3.18"
-
Affected
Siemens
Search vendor "Siemens"
Simit Simulation Platform
Search vendor "Siemens" for product "Simit Simulation Platform"
>= 10.0 < 10.3
Search vendor "Siemens" for product "Simit Simulation Platform" and version " >= 10.0 < 10.3"
-
Affected
Siemens
Search vendor "Siemens"
Simit Simulation Platform
Search vendor "Siemens" for product "Simit Simulation Platform"
10.3
Search vendor "Siemens" for product "Simit Simulation Platform" and version "10.3"
-
Affected
Siemens
Search vendor "Siemens"
Sinec Infrastructure Network Services
Search vendor "Siemens" for product "Sinec Infrastructure Network Services"
< 1.0.1.1
Search vendor "Siemens" for product "Sinec Infrastructure Network Services" and version " < 1.0.1.1"
-
Affected
Siemens
Search vendor "Siemens"
Sinec Infrastructure Network Services
Search vendor "Siemens" for product "Sinec Infrastructure Network Services"
1.0.1
Search vendor "Siemens" for product "Sinec Infrastructure Network Services" and version "1.0.1"
-
Affected
Siemens
Search vendor "Siemens"
Sinema Remote Connect Server
Search vendor "Siemens" for product "Sinema Remote Connect Server"
< 3.0
Search vendor "Siemens" for product "Sinema Remote Connect Server" and version " < 3.0"
-
Affected
Siemens
Search vendor "Siemens"
Sinema Remote Connect Server
Search vendor "Siemens" for product "Sinema Remote Connect Server"
3.0
Search vendor "Siemens" for product "Sinema Remote Connect Server" and version "3.0"
-
Affected
Siemens
Search vendor "Siemens"
Sinema Remote Connect Server
Search vendor "Siemens" for product "Sinema Remote Connect Server"
3.0
Search vendor "Siemens" for product "Sinema Remote Connect Server" and version "3.0"
sp1
Affected
Siemens
Search vendor "Siemens"
Simatic Process Historian
Search vendor "Siemens" for product "Simatic Process Historian"
>= 2019 < 2020
Search vendor "Siemens" for product "Simatic Process Historian" and version " >= 2019 < 2020"
-
Affected
Siemens
Search vendor "Siemens"
Simatic Process Historian
Search vendor "Siemens" for product "Simatic Process Historian"
2020
Search vendor "Siemens" for product "Simatic Process Historian" and version "2020"
-
Affected