SB2021073002 - Multiple vulnerabilities in Wibu-Systems CodeMeter Runtime
Published: July 30, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2021-20094)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition. A remote attacker can send a specially crafted packet to the CodeMeter Runtime CmWAN server, trigger out-of-bounds read error and cause a denial of service condition on the system.
2) Out-of-bounds read (CVE-ID: CVE-2021-20093)
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition. A remote attacker can send a specially crafted packet, trigger out-of-bounds read error and read contents of memory on the system or cause a denial of service condition.
Remediation
Install update from vendor's website.
References
- https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-02.pdf
- https://www.tenable.com/security/research/tra-2021-24
- https://cert-portal.siemens.com/productcert/pdf/ssa-675303.pdf
- https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-01.pdf