CVE-2020-14515: High severity wibu-systems ag vulnerability
CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this CodeMeter vulnerability?
The vulnerability ID for this CodeMeter vulnerability is CVE-2020-14515.
What is the severity of vulnerability CVE-2020-14515?
The severity of vulnerability CVE-2020-14515 is high with a CVSS score of 7.5.
Which versions of CodeMeter are affected by CVE-2020-14515?
All versions prior to 6.90 of CodeMeter are affected by CVE-2020-14515.
What is the impact of this vulnerability?
This vulnerability allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file.
Is there a fix for CVE-2020-14515 vulnerability?
Yes, the fix for CVE-2020-14515 is to update CodeMeter to version 6.90 or later.