Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:NGemalto Sentinel Ldk
APPGemalto< 7.92
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-8283MEDIUM6.5same product
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This...
CVE-2017-11497CRITICAL9.8PL ✓same vendor
Stack buffer overflow w Gemalto Sentinel LDK — RCE przez złośliwy pakiet językowy
CVE-2017-11496CRITICAL9.8PL ✓same vendor
Stack buffer overflow w Gemalto Sentinel LDK umożliwiający zdalne wykonanie kodu
CVE-2019-18232HIGH7.8same vendor
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected...
CVE-2019-9156HIGH8.0same vendor
Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.