CVE-2017-12819
Summary
| CVE | CVE-2017-12819 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-04 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Siemens Building Technologies Products (Update A) | CISA |
MISC |
ics-cert.us-cert.gov |
|
| KLCERT-17-005: Sentinel LDK RTE: Remote manipulations with language pack updater lead to NTLM-relay attack for system user | Kaspersky ICS CERT |
MISC |
ics-cert.kaspersky.com |
Third Party Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590561 GE Common Licensing Multiple Vulnerabilities (GED SecComm 18-02)
- 590593 GE Common Licensing Multiple Vulnerabilities (GED SecComm 18-02)