Vulnerabilities > Sentinel

DATE CVE VULNERABILITY TITLE RISK
2017-10-04 CVE-2017-12822 Missing Authentication for Critical Function vulnerability in Sentinel LDK RTE Firmware
Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.
network
low complexity
sentinel CWE-306
7.5
2017-10-04 CVE-2017-12821 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution.
network
low complexity
sentinel CWE-119
7.5
2017-10-04 CVE-2017-12820 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
network
low complexity
sentinel CWE-119
5.0
2017-10-04 CVE-2017-12819 Improper Authentication vulnerability in Sentinel LDK RTE Firmware
Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55.
network
low complexity
sentinel CWE-287
7.5
2017-10-04 CVE-2017-12818 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware
Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
network
low complexity
sentinel CWE-119
5.0