Impact
The vulnerability is triggered when CodeMeter Runtime is used in server mode. Early builds before 8.41a and 9.10 use a weak cryptographic SID as the only authentication token for a session. An attacker can brute‑force this SID, obtain another user's session handle, and read the license data stored in that handle. The result is unauthorized disclosure of proprietary license information and a confidentiality breach that could aid further attacks.
Affected Systems
Affected is Wibu Systems AG CodeMeter Runtime. Any installation of the runtime before version 8.41a or before 9.10 that is configured as a server is vulnerable. Versions 6.x, 7.x, 8.x up to 8.40, and 9.x up to 9.09 match the CPE entries and are therefore within scope.
Risk and Exploitability
The CVSS score of 7.7 marks the flaw as high severity. Although EPSS data is missing and the vulnerability is not yet in the CISA KEV catalog, the weakness can be exploited by anyone who can reach the server interface. The attacker simply needs to find the SID field, perform a brute‑force search, and once a valid SID is found, the corresponding session handle reveals the license data. The lack of additional privilege requirements and the straightforward attack path make it a significant risk for exposed CodeMeter Runtime servers.
OpenCVE Enrichment