Sept. 12, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

WIBU Systems published information about a heap buffer overflow vulnerability and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products for license management.


The vulnerability is described in the section “Vulnerability Classification” below and got assigned the CVE ID CVE-2023-3935. Successful exploitation of this vulnerability could allow



  • an unauthenticated remote attacker to execute code on vulnerable products, where CodeMeter Runtime (i.e., CodeMeter.exe) is configured as a server, or

  • an authenticated …

buffer buffer overflow buffer overflow vulnerability classification cve fix heap buffer overflow industrial information license management overflow product products releases runtime siemens ssa systems vulnerability

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Sr Security Engineer - Colombia

@ Nubank | Colombia, Bogota

Security Engineer, Investigations - i3

@ Meta | Menlo Park, CA | Washington, DC | Remote, US

Cyber Security Engineer

@ ASSYSTEM | Bridgwater, United Kingdom

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States