Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vcw-h879-447q

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

EPSS

Процентиль: 39%
0.00456
Низкий

8.6 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.6
nvd
26 дней назад

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

EPSS

Процентиль: 39%
0.00456
Низкий

8.6 High

CVSS3

Дефекты

CWE-284