CVE-2020-14509
Summary
| CVE | CVE-2020-14509 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-16 20:15:00 UTC |
| Updated | 2021-11-04 18:22:00 UTC |
| Description | Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Wibu-Systems CodeMeter (Update A) | CISA | MISC | us-cert.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590727 WIBU CodeMeter PASVisu Multiple Vulnerabilities
- 590734 WIBU Codemeter Runtime PAS4000 Multiple Vulnerabilities (adv_1005485-de-02)
- 590802 Siemens Remote Connect Client Multiple Vulnerabilities (SSA-455843)
- 590878 Schneider Electric Wibu-Systems CodeMeter Multiple Vulnerabilities (SEVD-2020-287-02)