QID 375649

Date Published: 2021-06-24

QID 375649: Wibu-Systems CodeMeter Runtime Denial Of Service Vulnerability

CodeMeter is a technology of Wibu-Systems providing secure protection and effective license management of software and digital content.

CVE-2021-20093: An attacker could send a specially crafted packet that could have the CodeMeter Runtime Network Server send back packets containing data from the heap or crash the server.
CVE-2021-20094: An attacker could send a specially crafted packet to the CodeMeter Runtime CmWAN server to cause a Denial of Service.
Affected Versions:
CodeMeter Runtime versions prior to 7.21a

QID detection Logic (Authenticated and Un-Authenticated):
This checks for vulnerable version of CodeMeter Runtime.

Successful exploitation may allow an attacker to cause CodeMeter Runtime Server (i.e., CodeMeter.exe) to crash.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Upgrade to CodeMeter Runtime 7.21a or newer .

    Download here.

    CVEs related to QID 375649

    Software Advisories
    Advisory ID Software Component Link
    WIBU-210423-01 URL Logo cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-01.pdf
    WIBU-210423-02 URL Logo cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/Advisory_WIBU-210423-02.pdf