PT-2026-82478 · Unknown · Codemeter Runtime
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CodeMeter Runtime versions prior to 8.41a
CodeMeter Runtime versions prior to 9.10
Description
When configured as a server, the software accepts requests using opcode 0x5e that include a data length value and the associated data. A lack of bounds checking on the data length value allows for out-of-bounds reads, which can trigger a segmentation fault—a memory access violation—resulting in a crash of the CodeMeter Runtime.
Recommendations
Update CodeMeter Runtime to version 8.41a or later.
Update CodeMeter Runtime to version 9.10 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codemeter Runtime