IM
IronMonkey Threat Research

CVE-2020-14515 HIGH

Published: 2020-09-16 | Last Modified: 2024-11-21 | Status: Modified

Description

CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.

Additional Descriptions (1)

CodeMeter (todas las versiones anteriores a 6.90 cuando se utilizan archivos de actualización con CmActLicense Firm Code) presenta un problema en el mecanismo de comprobación de firmas de archivos de licencia, que permite a atacantes crear archivos de licencia arbitrarios, incluyendo la falsificación de un archivo de licencia válido como si fuera un archivo de licencia válido de un proveedor existente. Solo están afectados los archivos de actualización de CmActLicense con CmActLicense Firm Code

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-347

Affected Products

Vendor Product Version Update Type
wibu codemeter * <built-in method update of dict object at 0x7e60a87b6d40> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:wibu:codemeter:*:*:*:*:*:*:*:*

References

Notification
Message here