Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01 | third party advisory us government resource |