SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14509

Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields.

CRITICAL 9.8EPSS 2.07%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.07% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-805
Affected
wibu/codemeter
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.