Zurück zur Übersicht

Endress+Hauser: Multiple products affected by Wibu-Systems CodeMeter Vulnerability

VDE-2025-105
Last update
08.12.2025 10:00
Published at
08.12.2025 10:00
Vendor(s)
Endress+Hauser AG
External ID
VDE-2025-105
CSAF Document

Summary

A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.

Impact

An attacker exploiting the vulnerability in Wibu CodeMeter Runtime when running in server mode could gain full control of the affected server via network access without any user interaction. In non-networked workstation mode, exploiting the same vulnerability could result in privilege escalation, granting the attacker full administrative access to the workstation.

Affected Product(s)

Model no. Product name Affected versions
DeviceCare <1.07.05 DeviceCare <1.07.05
FDM installations <1.6.13.10138 FDM installations <1.6.13.10138
FieldCare <2.16.00 FieldCare <2.16.00
Proline Promag 800 OPC UA Connectivity vers:all/* Proline Promag 800 OPC UA Connectivity vers:all/*
SupplyCare Enterprise <3.14 SupplyCare Enterprise <3.14

Vulnerabilities

Expand / Collapse all

Published
08.12.2025 10:28
Weakness
Out-of-bounds Write (CWE-787)
Summary

A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

References

Mitigation

If possible, configure CodeMeter to run in client-only mode. If server mode is required, restrict access to authorized clients by implementing an access control list.
For Proline Promag 800 OPC UA Connectivity, CodeMeter operates as a server only during license activation. Installation and license activation are managed by Endress+Hauser. If a customer performs manual license activation, it is strongly recommended to limit network access to necessary clients only by using firewalls or equivalent security measures.

Remediation

Endress+Hauser has released updated firmware versions that address this vulnerability. The only exception is Proline Promag 800 OPC UA Connectivity, with the update planned for Q3 2026. Customers are strongly advised to upgrade to the latest fixed version. For assistance, please contact your local Endress+Hauser service center.

Product Fixed Version
DeviceCare 1.07.05
FDM installations 1.6.13.10138
FieldCare 2.16.00
SupplyCare Enterprise 3.14

Acknowledgments

Endress+Hauser AG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 08.12.2025 10:00 Initial version