CVE-2020-14517

CRITICAL

CodeMeter < 6.90 - Use of a Broken or Risky Cryptographic Algorithm

Title source: llm
STIX 2.1

Description

Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 46.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-327 CWE-326
Status published
Products (1)
wibu/codemeter < 6.90
Published Sep 16, 2020
Tracked Since Feb 18, 2026