CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Phoenixcontact TrumpfWibu24Activation Wizard Codemeter RuntimeE Mobility Charging Suite+21 moreNov 21, 2024 Sep 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. |
2Siemens Wibu10Codemeter Runtime Pss CapePss E+7 moreNov 21, 2024 Nov 14, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. |
Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file. |
Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attackers to cause a denial of service (CodeMeter.exe crash) via certain crafted packets to TCP port 22350. |