{"api_version":"1","generated_at":"2026-07-24T18:41:02+00:00","cve":"CVE-2017-11497","urls":{"html":"https://cve.report/CVE-2017-11497","api":"https://cve.report/api/cve/CVE-2017-11497.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-11497","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-11497"},"summary":{"title":"CVE-2017-11497","description":"Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via language packs containing filenames longer than 1024 characters.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-10-03 01:29:00","updated_at":"2018-05-11 01:29:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01","refsource":"MISC","tags":[],"title":"Siemens Building Technologies Products (Update A) | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.iotvillage.org/slides_dc25/Sergey_Vlad_DEFCON_IOT_Village_Public2017.pptx","name":"https://www.iotvillage.org/slides_dc25/Sergey_Vlad_DEFCON_IOT_Village_Public2017.pptx","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"application/vnd.openxmlformats-officedocument.presentationml.presentation","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102906","name":"102906","refsource":"BID","tags":[],"title":"Gemalto Sentinel License Manager Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-018-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-018-01","refsource":"MISC","tags":[],"title":"Siemens SIMATIC WinCC Add-On | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://ics-cert.kaspersky.com/advisories/2017/07/28/klcert-17-002-sentinel-ldk-rte-language-packs-containing-malformed-filenames-lead-to-remote-code-execution/","name":"https://ics-cert.kaspersky.com/advisories/2017/07/28/klcert-17-002-sentinel-ldk-rte-language-packs-containing-malformed-filenames-lead-to-remote-code-execution/","refsource":"MISC","tags":["Third Party Advisory"],"title":"KLCERT-17-002: Sentinel LDK RTE: language packs containing malformed filenames lead to Remote Code Execution | Kaspersky ICS CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102739","name":"102739","refsource":"BID","tags":[],"title":"Multiple Siemens SIMATIC WinCC Add-On Products Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf","name":"https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf","refsource":"CONFIRM","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-11497","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11497","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"7.50","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11497","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gemalto","cpe5":"sentinel_ldk_rte","cpe6":"7.50","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-11497","qid":"590561","title":"GE Common Licensing Multiple Vulnerabilities (GED SecComm 18-02)"},{"cve":"CVE-2017-11497","qid":"590593","title":"GE Common Licensing Multiple Vulnerabilities (GED SecComm 18-02)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-11497","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via language packs containing filenames longer than 1024 characters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-093-01"},{"name":"https://ics-cert.kaspersky.com/advisories/2017/07/28/klcert-17-002-sentinel-ldk-rte-language-packs-containing-malformed-filenames-lead-to-remote-code-execution/","refsource":"MISC","url":"https://ics-cert.kaspersky.com/advisories/2017/07/28/klcert-17-002-sentinel-ldk-rte-language-packs-containing-malformed-filenames-lead-to-remote-code-execution/"},{"name":"https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf","refsource":"CONFIRM","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-727467.pdf"},{"name":"102906","refsource":"BID","url":"http://www.securityfocus.com/bid/102906"},{"name":"https://www.iotvillage.org/slides_dc25/Sergey_Vlad_DEFCON_IOT_Village_Public2017.pptx","refsource":"MISC","url":"https://www.iotvillage.org/slides_dc25/Sergey_Vlad_DEFCON_IOT_Village_Public2017.pptx"},{"name":"102739","refsource":"BID","url":"http://www.securityfocus.com/bid/102739"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-018-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-018-01"}]}},"nvd":{"publishedDate":"2017-10-03 01:29:00","lastModifiedDate":"2018-05-11 01:29:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gemalto:sentinel_ldk_rte:3.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gemalto:sentinel_ldk_rte:7.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gemalto:sentinel_ldk_rte:2.10:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gemalto:sentinel_ldk_rte:7.50:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"11497","Ordinal":"108640","Title":"CVE-2017-11497","CVE":"CVE-2017-11497","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"11497","Ordinal":"1","NoteData":"Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via language packs containing filenames longer than 1024 characters.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"11497","Ordinal":"2","NoteData":"2017-10-02","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"11497","Ordinal":"3","NoteData":"2018-05-10","Type":"Other","Title":"Modified"}]}}}