High severity7.1NVD Advisory· Published Nov 14, 2021· Updated Jun 17, 2026
CVE-2021-41057
CVE-2021-41057
Description
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14<7.30a+ 1 more
- (no CPE)range: <7.30a
- cpe:2.3:a:wibu:codemeter_runtime:*:*:*:*:*:*:*:*range: <7.30a
- WIBU/CodeMeter Runtimedescription
- cpe:2.3:a:siemens:pss_cape:14:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_information_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:simatic_information_server:*:*:*:*:*:*:*:*range: <2019
- cpe:2.3:a:siemens:simatic_information_server:2019:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_information_server:2019:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_process_historian:*:*:*:*:*:*:*:*Range: <=2019
Patches
Vulnerability mechanics
References
3- cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210910-01.pdfnvdMitigationVendor Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-580693.pdfnvdThird Party Advisory
- www.wibu.com/us/support/security-advisories.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.