Back to Database
Status published
High
CVE-2017-12820
Arbitrary memory read from controlled memory pointer in Gemalto's HASP...
Vulnerability Description
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-12820
Credits & Attribution
No credits recorded in the NVD database.
References
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2017/10/02/klcert-17-006-sentinel-ldk-rte-arbitrary-memory-read-from-controlled-memory-pointer-leads-to-remote-denial-of-service/
- https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01
- https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf
- http://www.securityfocus.com/bid/102906
More from Gemalto
View All →CVE-2019-6534
The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro...
High
7.8
CVE-2018-6305
Denial of service in Gemalto's Sentinel LDK RTE version before...
High
7.5
CVE-2018-6304
Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE...
High
7.5
CVE-2017-12822
Remote enabling and disabling admin interface in Gemalto's HASP SRM,...
Critical
9.9
CVE-2017-12821
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel...
Critical
9.8
Affected Vendor
Gemalto
View all reports →Affected Software
Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE
Vulnerable Versions:
7.55
Timeline
Official Publish:
October 3rd, 2017
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.