First published: Mon Oct 02 2017(Updated: )
Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote process (a denial of service) via a language pack (ZIP file) with invalid HTML files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thales Sentinel LDK | =2.10 | |
Thales Sentinel LDK | =3.0 | |
Thales Sentinel LDK | =7.1 | |
Thales Sentinel LDK | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11498 is classified as a high severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2017-11498, update to the latest version of Sentinel LDK that addresses the buffer overflow vulnerability.
CVE-2017-11498 impacts all versions of Gemalto ACC from HASP SRM 2.10 to Sentinel LDK 7.50.
Yes, CVE-2017-11498 can be exploited remotely using a malicious language pack containing invalid HTML files.
Exploiting CVE-2017-11498 can lead to a denial of service, causing the affected remote process to shut down.