CyberRota Analysis
AI-GeneratedCodeMeter Runtime versions prior to 8.41a and 9.10 are vulnerable due to the use of a cryptographically weak session identifier (SID) for authentication, which allows attackers to brute-force the SID and access session handles. This could lead to unauthorized reading of license information from other sessions, posing a significant risk to data confidentiality. Organizations using CodeMeter Runtime in server configurations should prioritize patching to mitigate this vulnerability.
Original NVD Description
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.