VYPR
Unrated severityNVD Advisory· Published Sep 16, 2020· Updated Aug 4, 2024

CVE-2020-14517

CVE-2020-14517

Description

Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Protocol encryption in CodeMeter Runtime (versions prior to 6.90, or 6.90+ when running as server) is easily broken, enabling remote attackers to communicate with the API and potentially execute arbitrary code.

Vulnerability

The vulnerability exists in CodeMeter Runtime, a license manager by Wibu-Systems AG. It affects all versions prior to 6.90, as well as version 6.90 or newer if CodeMeter Runtime is running as a server and accepts external connections. The protocol encryption can be easily broken, allowing an attacker to remotely communicate with the CodeMeter API. [1]

Exploitation

An attacker can exploit this weakness remotely with low attack complexity and without authentication or user interaction. The attacker sends specially crafted packets to the CodeMeter service, which the packet parser processes without properly verifying length fields, leading to buffer access with incorrect length value. [1]

Impact

Successful exploitation could allow an attacker to alter and forge license files, cause a denial-of-service condition, potentially achieve remote code execution, read heap data, and disrupt the normal operation of third-party software that depends on CodeMeter. The CVSS v3 base score is 10.0, with the vector string (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicating complete compromise of confidentiality, integrity, and availability across system boundaries. [1]

Mitigation

Wibu-Systems has released a fix in CodeMeter Runtime version 7.10a. According to CISA, all versions prior to 7.10a are affected by CVE-2020-14517. Users should update to version 7.10a or later. If immediate patching is not possible, restricting network access to the CodeMeter service and ensuring it does not accept external connections can reduce risk. This vulnerability is not currently on the CISA Known Exploited Vulnerabilities (KEV) catalog. [1]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • CodeMeter/CodeMeterdescription
  • Wibu/Codemeterllm-fuzzy
    Range: <6.90; >=6.90 if running as server

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.