Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77f6-gh77-3f4f

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.

CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.

EPSS

Процентиль: 25%
0.00085
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость компонента CmActLicense приложения контроля лицензий CodeMeter, позволяющая нарушителю переименовать произвольные файлы

EPSS

Процентиль: 25%
0.00085
Низкий