Wibu-Systems AG Update
2955Warning Date
Severity Level
Warning Number
Target Sector
10 September, 2020
● High
2020-1750
All - Manufacturing
Description:
Wibu-Systems AG has released a security update to address a vulnerability in the following product:
- CodeMeter Runtime
- All versions prior to 7.10 .
- All versions prior to 7.00 including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server.
- All versions prior to 6.81 .
- All versions prior to 6.90 including Version 6.90 or newer only if CodeMeter Runtime is running as server.
- All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code.
Threats:
An attacker could exploit this vulnerability by doing the following:
- Execute arbitrary code remotely..
Best practice and Recommendations:
The CERT team encourages users to apply the Wibu-Systems AG update according to the below link: