Your review has been sent successfully

Wibu-Systems AG Update

2955
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

10 September, 2020

● High

2020-1750

All - Manufacturing

Description:

Wibu-Systems AG has released a security update to address a vulnerability in the following product:

  • CodeMeter Runtime
    • All versions prior to 7.10 .
    • All versions prior to 7.00 including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server.
    • All versions prior to 6.81 .
    • All versions prior to 6.90 including Version 6.90 or newer only if CodeMeter Runtime is running as server.
    • All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code.

Threats:

An attacker could exploit this vulnerability by doing the following:

  • Execute arbitrary code remotely..

Best practice and Recommendations:

The CERT team encourages users to apply the Wibu-Systems AG update according to the below link:

Last updated at 10 September, 2020

Rate the content

rate-icon
up icon