Lucene search

K
cvelistIcscertCVELIST:CVE-2020-14515
HistorySep 16, 2020 - 7:48 p.m.

CVE-2020-14515

2020-09-1619:48:08
CWE-347
icscert
www.cve.org
9
codemeter
vulnerability
license-file signature

EPSS

0.001

Percentile

34.6%

CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.

CNA Affected

[
  {
    "product": "CodeMeter",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code."
      }
    ]
  }
]

EPSS

0.001

Percentile

34.6%

Related for CVELIST:CVE-2020-14515