PT-2026-82479 · Unknown · Codemeter Runtime
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CodeMeter Runtime versions prior to 8.41a
CodeMeter Runtime versions prior to 9.10
Description
When configured as a server, the software issues handles per connection and uses a cryptographically weak SID (Session Identifier) as the only method of authentication. This allows an attacker to brute-force the
SID, recover the handle number of another session, and read license information associated with that handle.Recommendations
Update CodeMeter Runtime to version 8.41a or later.
Update CodeMeter Runtime to version 9.10 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codemeter Runtime