QID 590727

Date Published: 2022-03-28

QID 590727: WIBU CodeMeter PASVisu Multiple Vulnerabilities

Several software tools from Mushroom use the CodeMeter runtime application of the company WIBU-SYSTEMS AG for the management of licenses.
This application contains several vulnerabilities, which allow an attacker to modify and falsify a license file, prevent normal operation of CodeMeter (Denial-of-Service), and possibly execute arbitrary code.

AFFECTED PRODUCTS
PASvisu software: all versions up to 1.9.0

QID detection logic:(Authenticated): The QID checks for PASvisuServer.exe file version to detect the vulnerable version.

Successful exploitation of this vulnerabilities can lead to denial of service and arbitrary code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section CVE-2020-14509 for affected packages and patching details.

    CVEs related to QID 590727

    Software Advisories
    Advisory ID Software Component Link