CVE-2020-16233: High severity wibu-systems ag vulnerability
Published Sep 16, 2020
·Updated
An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.
Affected Software
6 affected components
Wibu-Systems AG All versions prior to 7.10a are affected by CVE-2020-14509 and CVE-2020-14519
Wibu-Systems AG All versions prior to 7.10a are affected by CVE-2020-14517
Wibu-Systems AG All versions prior to 7.10 are affected by CVE-2020-16233
Wibu-Systems AG All versions prior to 6.81 are affected by CVE-2020-14513
Wibu-Systems AG All versions prior to 6.90 are affected by CVE-2020-14515 when using CmActLicense update files with CmActLicense Firm Code
Wibu CodeMeter<7.10
Event History
Sep 16, 2020
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-16233?
CVE-2020-16233 is a vulnerability in CodeMeter that allows an attacker to send a specially crafted packet to retrieve data from the heap.
2
Which versions of CodeMeter are affected by CVE-2020-16233?
All versions prior to 7.10 of CodeMeter are affected by CVE-2020-16233.
3
How severe is CVE-2020-16233?
CVE-2020-16233 has a severity rating of 7.5, which is classified as high.
4
How can I fix CVE-2020-16233?
To fix CVE-2020-16233, it is recommended to upgrade CodeMeter to version 7.10 or later.
5
Where can I find more information about CVE-2020-16233?
You can find more information about CVE-2020-16233 in the advisory published by US-CERT at the following URL: https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01.