Back to Database
Status published
Critical
CVE-2017-12822
Remote enabling and disabling admin interface in Gemalto's HASP SRM,...
Vulnerability Description
Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-12822
Credits & Attribution
No credits recorded in the NVD database.
References
- https://ics-cert.kaspersky.com/advisories/klcert-advisories/2017/10/02/klcert-17-008-sentinel-ldk-rte-remote-enabling-and-disabling-admin-interface/
- https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01
- https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf
- http://www.securityfocus.com/bid/102906
More from Gemalto
View All →CVE-2019-6534
The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro...
High
7.8
CVE-2018-6305
Denial of service in Gemalto's Sentinel LDK RTE version before...
High
7.5
CVE-2018-6304
Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE...
High
7.5
CVE-2017-12821
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel...
Critical
9.8
CVE-2017-12820
Arbitrary memory read from controlled memory pointer in Gemalto's HASP...
High
7.5
Affected Vendor
Gemalto
View all reports →Affected Software
Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE
Vulnerable Versions:
7.55
Timeline
Official Publish:
October 3rd, 2017
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.