Memory Corruption Vulnerabilities in CodeMeter by Wibu-Systems
CVE-2020-14509

9.8CRITICAL

Key Information:

Vendor

Wibu

Status
Vendor
CVE Published:
16 September 2020

What is CVE-2020-14509?

Multiple memory corruption vulnerabilities exist in CodeMeter due to improper verification of length fields within the packet parser mechanism. This flaw allows an attacker to craft specific packets that, when processed by the CodeMeter software, could lead to unexpected behavior or system compromise. Users are advised to upgrade to version 7.10 or later to mitigate the risk of exploitation.

Affected Version(s)

CodeMeter All versions prior to 7.10

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.