Impact
The CodeMeter Runtime servers lack enforcement of network-origin restrictions for certain configuration commands. As a result, any network client—regardless of location—can send commands that are intended to be restricted to local or same‑network clients. This flaw allows an attacker to read sensitive configuration data and modify entries in Server.ini, including the hash of the CodeMeter WebAdmin credentials, potentially enabling full administrative takeover of the WebAdmin interface.
Affected Systems
The vulnerability affects CodeMeter Runtime from Wibu Systems, specifically versions prior to 8.41a and prior to 9.10. These versions are identified by the CPE strings for wibu-systems-ag:codemeter-runtime across 6.x and 7.x branches.
Risk and Exploitability
The flaw receives a CVSS score of 8.6, indicating high severity. No EPSS score is provided, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. While the description does not list a public exploit, the conditions required are minimal: the target must be running one of the affected runtime versions and be configured as a server. The likely attack vector is over a network, whereby any remote peer can misuse the improper access controls to alter configuration settings.
OpenCVE Enrichment