Siemans WIBU Systems CodeMeter
WIBU Systems CodeMeter Runtime contains a heap buffer overflow vulnerability (CVE-2023-3935) in license management software used by multiple Siemens industrial products. Successful exploitation allows unauthenticated remote code execution on systems where CodeMeter Runtime is configured as a server, or authenticated local privilege escalation on systems where it is configured as a client. Affects PSS(R)CAPE, PSS(R)E, PSS(R)ODMS, SIMATIC PCS neo, SIMATIC WinCC OA, SIMIT Simulation Platform, SINEC INS, and SINEMA Remote Connect.
- Network access to CodeMeter Runtime when configured as server (typically port 22350 or other configured ports)
- Local system access with user-level credentials when CodeMeter Runtime is configured as client
- CodeMeter Runtime version prior to 7.60c
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f2d578d2-9522-4d49-acd4-a35b3dc0977fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.