A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2021-24 | exploit third party advisory patch |
https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-01.pdf | mitigation vendor advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-675303.pdf | third party advisory patch |
https://us-cert.cisa.gov/ics/advisories/icsa-21-210-02 | third party advisory us government resource |