Improper Verification of Cryptographic Signature in CodeMeter Runtime - CVE-2020-14515
Published: September 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected software does not verify the cryptographic signature for data within the license-file signature checking mechanism. A remote attacker can build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor.
Affected software
SPPA-T3000
SPPA-S2000
SPPA-S3000
How to mitigate CVE-2020-14515
SPPA-T3000 - update to 19.017.20
SPPA-S2000 - update to 3.06P1
SPPA-S3000 - addressed in versions 3.04P6, 3.05P3