CVE-2017-12819

CRITICAL

Sentinel LDK RTE < 7.55 - Improper Authentication via Language Pack Updater

Title source: llm
STIX 2.1

Description

Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55.

Scores

CVSS v3 9.8
EPSS 0.0136
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
Gemalto/Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.55
sentinel/sentinel_ldk_rte_firmware < 7.50
Published Oct 04, 2017
Tracked Since Feb 18, 2026