CVE-2020-16233 describes a heap information disclosure vulnerability in all versions of Wibu CodeMeter prior to 7.10. An unauthenticated attacker could send a specially crafted network packet, causing CodeMeter to return heap data. This vulnerability carries a CVSS score of 7.5 (High), indicating a high confidentiality impact with no integrity or availability impact, and low attack complexity. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.10CPE matchmatch criteria | cpe:2.3:a:wibu:codemeter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
WIBU Systems CodeMeter Runtime Vulnerabilities in Rexroth Products
Sep 25, 2020WIBU Systems CodeMeter Runtime Vulnerabilities in Rexroth Products
Sep 25, 2020WIBU Systems CodeMeter Runtime Vulnerabilities in Rexroth Products
Sep 25, 2020WIBU Systems CodeMeter Runtime Vulnerabilities in Rexroth Products
Sep 25, 2020WIBU Systems CodeMeter Runtime Vulnerabilities in Rexroth Products
Sep 25, 2020