SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-20093

A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a.

CRITICAL 9.1EPSS 33.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 33.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS
33.30% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
wibu/codemeter · siemens/pss cape · siemens/sicam 230 firmware · siemens/simatic information server · siemens/simatic pcs neo · siemens/simatic wincc oa · siemens/simit simulation platform · siemens/sinec infrastructure network services · siemens/sinema remote connect server · siemens/simatic process historian
Source
vulnreport@tenable.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.