Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj9j-5pfx-gc7p

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

EPSS

Процентиль: 26%
0.00326
Низкий

7.7 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.7
nvd
20 дней назад

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

EPSS

Процентиль: 26%
0.00326
Низкий

7.7 High

CVSS3

Дефекты

CWE-639