PT-2026-82476 · Unknown · Codemeter Runtime
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
CodeMeter Runtime versions prior to 8.41a
CodeMeter Runtime versions prior to 9.10
Description
When configured as a server, the configuration command handler fails to enforce network-origin restrictions. This allows remote peers to execute commands that should be restricted to local or same-network clients. An attacker can read sensitive configuration data and modify values within the
Server.ini file, including the credential hash for the CodeMeter WebAdmin, which can lead to a full takeover of the WebAdmin interface.Recommendations
Update CodeMeter Runtime to version 8.41a or later.
Update CodeMeter Runtime to version 9.10 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codemeter Runtime