CVE-2017-12822

Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:o:sentinel:sentinel_ldk_rte_firmware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:10

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/102906 - () http://www.securityfocus.com/bid/102906 -
References () https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf -
References () https://ics-cert.kaspersky.com/advisories/klcert-advisories/2017/10/02/klcert-17-008-sentinel-ldk-rte-remote-enabling-and-disabling-admin-interface/ - Third Party Advisory () https://ics-cert.kaspersky.com/advisories/klcert-advisories/2017/10/02/klcert-17-008-sentinel-ldk-rte-remote-enabling-and-disabling-admin-interface/ - Third Party Advisory
References () https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01 - () https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01 -

Information

Published : 2017-10-04 01:29

Updated : 2024-11-21 03:10


NVD link : CVE-2017-12822

Mitre link : CVE-2017-12822

CVE.ORG link : CVE-2017-12822


JSON object : View

Products Affected

sentinel

  • sentinel_ldk_rte_firmware
CWE
CWE-306

Missing Authentication for Critical Function