The vendor explicitly identifies these products as affected by this CVE.
- Desigo CC family V5.0
- Desigo CC family V5.1
- Desigo CC family V6
- Desigo CC family V7
- SENTRON powermanager
- Summary
- In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege. (WIBU-230704-01)
- Remediation
- Install the patch (available at https://support.industry.siemens.com/cs/ww/en/view/109825787/), which can be applied to all released versions
