CVE-2020-14513: Input Validation
Published Sep 16, 2020
·Updated
CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.
Affected Software
6 affected components
Wibu-Systems AG All versions prior to 7.10a are affected by CVE-2020-14509 and CVE-2020-14519
Wibu-Systems AG All versions prior to 7.10a are affected by CVE-2020-14517
Wibu-Systems AG All versions prior to 7.10 are affected by CVE-2020-16233
Wibu-Systems AG All versions prior to 6.81 are affected by CVE-2020-14513
Wibu-Systems AG All versions prior to 6.90 are affected by CVE-2020-14515 when using CmActLicense update files with CmActLicense Firm Code
Wibu CodeMeter<6.81
Event History
Sep 16, 2020
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-14513?
CVE-2020-14513 is a vulnerability in CodeMeter and the software using it, where it may crash while processing a specifically crafted license file due to unverified length fields.
2
What is the severity of CVE-2020-14513?
CVE-2020-14513 has a severity rating of high, with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2020-14513?
All versions of CodeMeter prior to 6.81 are affected by CVE-2020-14513.
4
How can CVE-2020-14513 be exploited?
CVE-2020-14513 can be exploited by processing a specifically crafted license file containing unverified length fields.
5
Is there a fix for CVE-2020-14513?
Yes, updating CodeMeter to version 6.81 or later will fix CVE-2020-14513.