CVE-2020-14519
HIGHCodeMeter < 7.00 - Origin Validation Error via WebSockets API
Title source: llmDescription
This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01
Scores
CVSS v3
7.5
EPSS
0.0064
EPSS Percentile
45.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-346
Status
published
Products (1)
wibu/codemeter
< 7.00
Published
Sep 16, 2020
Tracked Since
Feb 18, 2026