{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"A vulnerability is reported in WIBU-SYSTEMS Codemeter. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) installations. All currently existing e!COCKPIT installation bundles and WAGO-I/O-Pro (CODESYS 2.3) installation bundles are affected with vulnerable versions of WIBU-SYSTEMS Codemeter.","title":"Summary"},{"category":"description","text":"WAGO controllers and IO-Devices are not affected by WIBU-SYSTEMS Codemeter vulnerabilities. However, due to compatibility reasons to the CODESYS Group CODESYS store, the e!COCKPIT and engineering software is bundled with a WIBU-SYSTEMS Codemeter installation.","title":"Impact"},{"category":"description","text":"- Use general security best practices to protect systems from local and network attacks.\n- Disable the container type 'Mass Storage' in CodeMeter via the Windows Registry.","title":"Mitigation"},{"category":"description","text":"We strongly encourage e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) users to update WIBU-SYSTEMS Codemeter by installing the latest available stand-alone WIBU-SYSTEMS Codemeter Version.\n\nWAGO will provide updated e!COCKPIT setup routines (Version 1.11) with the latest WIBU- SYSTEMS Codemeter version in Q2/2022.\n\nAdditionally WAGO will provide a security patch for e!COCKPIT Version 1.10 in February 2022.\nWAGO will provide updated WAGO-I/O-Pro (CODESYS 2.3) (Version 2.3.9.68) setup routines with the latest WIBU-SYSTEMS Codemeter version in Q1/2022.\n\nFor further details on risk mitigation and impact of this vulnerability, please refer to the official WIBU-SYSTEMS Advisory WIBU-210910-01 at Website https://www.wibu.com/support/security-advisories.html external link.\n\nFurther details on the corresponding CVEs can be obtained here:\nhttps://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210910-01.pdf external link","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@wago.com","name":"WAGO GmbH & Co. KG","namespace":"https://www.wago.com/psirt"},"references":[{"category":"self","summary":"VDE-2022-002: WAGO: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT and WAGO-I/O-Pro - HTML","url":"https://certvde.com/en/advisories/VDE-2022-002/"},{"category":"self","summary":"VDE-2022-002: WAGO: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT and WAGO-I/O-Pro - CSAF","url":"https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-002.json"},{"category":"external","summary":"Vendor PSIRT","url":"https://www.wago.com/psirt"},{"category":"external","summary":"CERT@VDE Security Advisories for WAGO GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/wago/"}],"title":"WAGO: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT and WAGO-I/O-Pro","tracking":{"aliases":["VDE-2022-002"],"current_release_date":"2025-05-22T13:03:10.000Z","generator":{"date":"2025-04-28T08:43:49.504Z","engine":{"name":"Secvisogram","version":"2.5.24"}},"id":"VDE-2022-002","initial_release_date":"2022-01-31T13:00:00.000Z","revision_history":[{"date":"2022-01-31T13:00:00.000Z","number":"1","summary":"Initial revision."},{"date":"2025-05-22T13:03:10.000Z","number":"2","summary":"Fix: quotation mark"}],"status":"final","version":"2"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<V1.11","product":{"name":"WAGO e!COCKPIT engineering software installation bundle <V1.11","product_id":"CSAFPID-51001"}},{"category":"product_version","name":"V1.11","product":{"name":"WAGO e!COCKPIT engineering software installation bundle V1.11","product_id":"CSAFPID-52001"}}],"category":"product_name","name":"WAGO e!COCKPIT engineering software installation bundle"},{"branches":[{"category":"product_version","name":"2.3.9.53","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.53","product_id":"CSAFPID-51002"}},{"category":"product_version","name":"2.3.9.68","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.68","product_id":"CSAFPID-52002"}},{"category":"product_version","name":"2.3.9.55","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.55","product_id":"CSAFPID-51003"}},{"category":"product_version","name":"2.3.9.61","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.61","product_id":"CSAFPID-51004"}},{"category":"product_version","name":"2.3.9.66","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.66","product_id":"CSAFPID-51005"}},{"category":"product_version","name":"2.3.9.46","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.46","product_id":"CSAFPID-51006"}},{"category":"product_version","name":"2.3.9.49","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.49","product_id":"CSAFPID-51007"}},{"category":"product_version","name":"2.3.9.47","product":{"name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation 2.3.9.47","product_id":"CSAFPID-51008"}}],"category":"product_name","name":"WAGO-I/O-Pro (CODESYS 2.3) engineering software installation"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"WAGO"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-51001","CSAFPID-51002","CSAFPID-51003","CSAFPID-51004","CSAFPID-51005","CSAFPID-51006","CSAFPID-51007","CSAFPID-51008"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-52001","CSAFPID-52002"],"summary":"Fixed products."}]},"vulnerabilities":[{"cve":"CVE-2021-41057","cwe":{"id":"CWE-59","name":"Improper Link Resolution Before File Access ('Link Following')"},"notes":[{"category":"description","text":"In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-52001","CSAFPID-52002"],"known_affected":["CSAFPID-51001","CSAFPID-51002","CSAFPID-51003","CSAFPID-51004","CSAFPID-51005","CSAFPID-51006","CSAFPID-51007","CSAFPID-51008"]},"remediations":[{"category":"mitigation","details":"Mitigation\n\nUse general security best practices to protect systems from local and network attacks.\nDisable the container type 'Mass Storage' in CodeMeter via the Windows Registry.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"We strongly encourage e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) users to update WIBU-SYSTEMS Codemeter by installing the latest available stand-alone WIBU-SYSTEMS Codemeter Version.\nWAGO will provide updated e!COCKPIT setup routines (Version 1.11) with the latest WIBU- SYSTEMS Codemeter version in Q2/2022.\nAdditionally WAGO will provide a security patch for e!COCKPIT Version 1.10 in February 2022.WAGO will provide updated WAGO-I/O-Pro (CODESYS 2.3) (Version 2.3.9.68) setup routines with the latest WIBU-SYSTEMS Codemeter version in Q1/2022.\nFor further details on risk mitigation and impact of this vulnerability, please refer to the official WIBU-SYSTEMS Advisory WIBU-210910-01 at Website https://www.wibu.com/support/security-advisories.html.\nFurther details on the corresponding CVEs can be obtained here:https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210910-01.pdf","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":7.1,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":7.1,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"products":["CSAFPID-51001","CSAFPID-51002","CSAFPID-51003","CSAFPID-51004","CSAFPID-51005","CSAFPID-51006","CSAFPID-51007","CSAFPID-51008"]}],"title":"CVE-2021-41057"}]}