Remote Code Execution Vulnerability in CodeMeter by WIBU-SYSTEMS
CVE-2020-14517

9.8CRITICAL

Key Information:

Vendor

Wibu

Status
Vendor
CVE Published:
16 September 2020

What is CVE-2020-14517?

The CodeMeter product from WIBU-SYSTEMS contains a vulnerability that allows unauthorized remote access due to broken protocol encryption. This affects all versions prior to 6.90 and may potentially expose sensitive API endpoints if the server setup permits external connections. Attackers can exploit this weakness to execute arbitrary commands, highlighting the importance of maintaining secure configurations and promptly applying necessary updates.

Affected Version(s)

CodeMeter All versions prior to 6.90, including Version 6.90 or newer only if CodeMeter Runtime is running as server.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.