CVE-2020-14519
Last modified
CVE-2020-14519 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wibu | Codemeter | < 7.00 |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-14519?
How severe is CVE-2020-14519?
How do I fix CVE-2020-14519?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-14513CodeMeter (All versions prior to 6.81) and the software usin…7.5
- CVE-2020-14514All trailer Power Line Communications are affected. PLC bus …4.3
- CVE-2020-14515CodeMeter (All versions prior to 6.90 when using CmActLicens…7.5
- CVE-2020-14516In Rockwell Automation FactoryTalk Services Platform Version…10
- CVE-2020-14517Protocol encryption can be easily broken for CodeMeter (All …9.8
- CVE-2020-14518Philips DreamMapper, Version 2.24 and prior. Information wri…5.3
- CVE-2020-1452<p>A remote code execution vulnerability exists in Microsoft…8.6
- CVE-2020-14520The affected product is vulnerable to an information leak, w…7.5
- CVE-2020-14521Multiple Mitsubishi Electric Factory Automation engineering …9.8
- CVE-2020-14522Softing Industrial Automation all versions prior to the late…7.5
- CVE-2020-14523Multiple Mitsubishi Electric Factory Automation products hav…9.8
- CVE-2020-14524Softing Industrial Automation all versions prior to the late…9.8
Are you affected by CVE-2020-14519?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
