Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.
https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01
https://www.tenable.com/blog/multiple-vulnerabilities-in-codemeter-leave-managed-industrial-control-systems-open-to-attack
Source: Mitre, NVD
Published: 2020-09-16
Updated: 2024-11-21
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.00366