CVE-2017-12819

Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55.
Configurations

Configuration 1 (hide)

cpe:2.3:o:sentinel:sentinel_ldk_rte_firmware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:10

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf -
References () https://ics-cert.kaspersky.com/advisories/klcert-advisories/2017/10/02/klcert-17-005-sentinel-ldk-rte-remote-manipulations-with-language-pack-updater-lead-to-ntlm-relay-attack-for-system-user/ - Third Party Advisory () https://ics-cert.kaspersky.com/advisories/klcert-advisories/2017/10/02/klcert-17-005-sentinel-ldk-rte-remote-manipulations-with-language-pack-updater-lead-to-ntlm-relay-attack-for-system-user/ - Third Party Advisory
References () https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01 - () https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01 -

Information

Published : 2017-10-04 01:29

Updated : 2024-11-21 03:10


NVD link : CVE-2017-12819

Mitre link : CVE-2017-12819

CVE.ORG link : CVE-2017-12819


JSON object : View

Products Affected

sentinel

  • sentinel_ldk_rte_firmware
CWE
CWE-287

Improper Authentication