As reported by industrial cybersecurity firm Claroty, certain vulnerabilities discovered in CodeMeter, a popular licensing and DRM product created by German Wibu-Systems, can expose industrial systems to remote attacks.

CodeMeter is designed to protect software from piracy and reverse engineering, offering license management capabilities, while also including security features that provide protection against hacking and other attacks.
CodeMeter can find many applications, but is often found in industrial products, including industrial computers, IIoT devices, and controllers. It is considered the successor to WibuKey, an older product that previously exposed industrial products from Siemens and other vendors to attacks due to serious vulnerabilities.
Claroty researchers have discovered six vulnerabilities in CodeMeter, some of which could be exploited to launch attacks against industrial control systems (ICS). Two of these vulnerabilities have been rated critical, while the rest are considered high severity.
Claroty reported its findings to the vendor in February and April 2019, who subsequently released updates in 2019 that patched some of the vulnerabilities.
Researchers discovered several types of flaws in CodeMeter, including memory corruption bugs and cryptographic flaws that can be exploited to modify or create license files.
In one attack scenario described by the researchers, an attacker creates a website designed to push a malicious permission to users' devices. The permission, when processed by CodeMeter, can allow a DoS attack or the execution of arbitrary code.
Claroty has created an online tool that allows users to check if they are running a vulnerable version of CodeMeter. The company has also created a GitHub page for the project.
