Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.
https://www.tenable.com/blog/multiple-vulnerabilities-in-codemeter-leave-managed-industrial-control-systems-open-to-attack
https://us-cert.cisa.gov/ics/advisories/icsa-20-203-01
Source: Mitre, NVD
Published: 2020-09-16
Updated: 2021-11-04
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical