Security restrictions bypass in Sentinel License Manager - CVE-2017-12822

 

Security restrictions bypass in Sentinel License Manager - CVE-2017-12822

Published: February 5, 2018


Vulnerability identifier: #VU10371
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12822
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to improper access controls. A remote attacker can enable license manager web interface as a default configuration and bypass security restrictions to perform further attacks.

Affected software

Sentinel License Manager
License Management System
Desigo ABT
Annual Shading
Siveillance Identity
SiteIQ Analytics
Desigo XWP
Desigo Configuration Manager

How to mitigate CVE-2017-12822

Update to version 7.6.


External References

Related Security Bulletins