Vulnerabilidad · Publicado 27/08/2026
CodeMeter Runtime versiones anteriores a 8.41a y 9.10 presentan una falla en la validación de origen de red que permite a atacantes remotos ejecutar comandos de configuración reservados para clientes locales o de la misma red. Un atacante puede leer datos sensibles del servidor y modificar valores en Server.ini, comprometiendo la integridad de sistemas que utilizan esta tecnología de licenciamiento en infraestructuras altas de empresas en LATAM.
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.
Score: 8.6/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CWE-284
Publicado en NIST NVD.