Heap-based buffer overflow in Sentinel License Manager - CVE-2017-12820

 

Heap-based buffer overflow in Sentinel License Manager - CVE-2017-12820

Published: February 5, 2018


Vulnerability identifier: #VU10370
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12820
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to heap-based buffer overflow when handling malicious input. A remote attacker can supply a specially crafted HTTP request body in Admin APIs, trigger memory corruption and cause the service to crash.

Affected software

Sentinel License Manager
License Management System
Desigo ABT
Annual Shading
Siveillance Identity
SiteIQ Analytics
Desigo XWP
Desigo Configuration Manager

How to mitigate CVE-2017-12820

Update to version 7.6.


External References

Related Security Bulletins