Vulnerabilidad · Publicado 27/08/2026
CodeMeter Runtime, cuando se configura como servidor, es vulnerable a un ataque de lectura fuera de límites (out-of-bounds read) mediante el opcode 0x5e debido a validación insuficiente de longitud de datos. Esta falla causa fallo de segmentación que interrumpe el servicio. Afecta sistemas de licenciamiento de software en empresas manufactureras, de ingeniería y financieras en LATAM que dependen de esta plataforma para protección de activos digitales.
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-130
Publicado en NIST NVD.