Vulnerabilities > Sentinel

DATE CVE VULNERABILITY TITLE RISK
2017-10-04 CVE-2017-12822 Missing Authentication for Critical Function vulnerability in Sentinel LDK RTE Firmware 7.50
Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.
network
low complexity
sentinel CWE-306
critical
9.9
2017-10-04 CVE-2017-12821 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware 7.50
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution.
network
low complexity
sentinel CWE-119
critical
9.8
2017-10-04 CVE-2017-12820 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware 7.50
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
network
low complexity
sentinel CWE-119
7.5
2017-10-04 CVE-2017-12819 Improper Authentication vulnerability in Sentinel LDK RTE Firmware 7.50
Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55.
network
low complexity
sentinel CWE-287
critical
9.8
2017-10-04 CVE-2017-12818 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware 7.50
Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
network
low complexity
sentinel CWE-119
7.5