VYPR

CodeMeter Runtime Server

by CodeMeter

CVEs (4)

  • CVE-2026-81573HigAug 27, 2026
    risk 0.56cvss 8.6epss 0.00

    If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can…

  • CVE-2026-81574HigAug 27, 2026
    risk 0.53cvss 8.2epss 0.00

    In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory…

  • CVE-2020-37017HigJan 29, 2026
    risk 0.51cvss 7.8epss 0.00

    CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that…

  • CVE-2026-81575HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that…