Security restrictions bypass in Sentinel License Manager - CVE-2017-12819
Published: April 4, 2018
Vulnerability identifier: #VU11503
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12819
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to improper access controls. A remote attacker can use language pack updater to bypass security restrictions, manipulate the system and perform NTLM-relay attack.
The weakness exists due to improper access controls. A remote attacker can use language pack updater to bypass security restrictions, manipulate the system and perform NTLM-relay attack.
Affected software
Sentinel License Manager
License Management System
Desigo ABT
Annual Shading
Siveillance Identity
SiteIQ Analytics
Desigo XWP
Desigo Configuration Manager
License Management System
Desigo ABT
Annual Shading
Siveillance Identity
SiteIQ Analytics
Desigo XWP
Desigo Configuration Manager
How to mitigate CVE-2017-12819
Update to version 7.6.