CVE-2017-11496
Summary
| CVE | CVE-2017-11496 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-03 01:29:00 UTC |
| Updated | 2018-05-11 01:29:00 UTC |
| Description | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via malformed ASN.1 streams in V2C and similar input files. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gemalto | Sentinel Ldk Rte | 2.10 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 3.0 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 7.1 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 7.50 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 2.10 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 3.0 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 7.1 | All | All | All |
| Application | Gemalto | Sentinel Ldk Rte | 7.50 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Siemens Building Technologies Products (Update A) | CISA | MISC | ics-cert.us-cert.gov | |
| www.iotvillage.org/slides_dc25/Sergey_Vlad_DEFCON_IOT_Village_Public2017.pptx | MISC | www.iotvillage.org | Third Party Advisory |
| Gemalto Sentinel License Manager Multiple Security Vulnerabilities | BID | www.securityfocus.com | |
| Multiple vulnerabilities found in popular license manager | Kaspersky ICS CERT | MISC | ics-cert.kaspersky.com | Third Party Advisory |
| Siemens SIMATIC WinCC Add-On | ICS-CERT | MISC | ics-cert.us-cert.gov | |
| Multiple Siemens SIMATIC WinCC Add-On Products Multiple Security Vulnerabilities | BID | www.securityfocus.com | |
| cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf | CONFIRM | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.