Summary
A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.
Impact
An attacker exploiting the vulnerability in Wibu CodeMeter Runtime when running in server mode could gain full control of the affected server via network access without any user interaction. In non-networked workstation mode, exploiting the same vulnerability could result in privilege escalation, granting the attacker full administrative access to the workstation.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| DeviceCare <1.07.05 | DeviceCare <1.07.05 | |
| FDM installations <1.6.13.10138 | FDM installations <1.6.13.10138 | |
| FieldCare <2.16.00 | FieldCare <2.16.00 | |
| Proline Promag 800 OPC UA Connectivity vers:all/* | Proline Promag 800 OPC UA Connectivity vers:all/* | |
| SupplyCare Enterprise <3.14 | SupplyCare Enterprise <3.14 |
Vulnerabilities
Expand / Collapse allA heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
Mitigation
If possible, configure CodeMeter to run in client-only mode. If server mode is required, restrict access to authorized clients by implementing an access control list.
For Proline Promag 800 OPC UA Connectivity, CodeMeter operates as a server only during license activation. Installation and license activation are managed by Endress+Hauser. If a customer performs manual license activation, it is strongly recommended to limit network access to necessary clients only by using firewalls or equivalent security measures.
Remediation
Endress+Hauser has released updated firmware versions that address this vulnerability. The only exception is Proline Promag 800 OPC UA Connectivity, with the update planned for Q3 2026. Customers are strongly advised to upgrade to the latest fixed version. For assistance, please contact your local Endress+Hauser service center.
| Product | Fixed Version |
|---|---|
| DeviceCare | 1.07.05 |
| FDM installations | 1.6.13.10138 |
| FieldCare | 2.16.00 |
| SupplyCare Enterprise | 3.14 |
Acknowledgments
Endress+Hauser AG thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 12/08/2025 10:00 | Initial version |