Stack-based buffer overflow in Sentinel License Manager - CVE-2017-12821
Published: February 5, 2018
Vulnerability identifier: #VU10369
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12821
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to stack-based buffer overflow when handling malicious input. A remote attacker can supply a specially crafted XML payload with more than supported number of elements, trigger memory corruption and cause the service to crash.
The weakness exists due to stack-based buffer overflow when handling malicious input. A remote attacker can supply a specially crafted XML payload with more than supported number of elements, trigger memory corruption and cause the service to crash.
Affected software
Sentinel License Manager
License Management System
Desigo ABT
Annual Shading
Siveillance Identity
SiteIQ Analytics
Desigo XWP
Desigo Configuration Manager
License Management System
Desigo ABT
Annual Shading
Siveillance Identity
SiteIQ Analytics
Desigo XWP
Desigo Configuration Manager
How to mitigate CVE-2017-12821
Update to version 7.6.