Search

Find a vulnerability

Search criteria

    6 vulnerabilities by Thalesgroup

    CVE-2026-3457 (GCVE-0-2026-3457)

    Vulnerability from cvelistv5 โ€“ Published: 2026-03-27 09:05 โ€“ Updated: 2026-09-03 15:44
    VLAI
    Title
    Stored XSS vulnerability in Sentinel ACC
    Summary
    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-03-27 13:06 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Thalesgroup Sentinel LDK Runtime Affected: 0 , < 10.22 (custom)
        cpe:2.3:a:thalesgroup:sentinel_ldk_runtime:*:*:windows:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-3457",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-27T13:06:20.772171Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-27T13:45:21.259Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "Sentinel LDK Runtime",
              "vendor": "Thalesgroup",
              "versions": [
                {
                  "lessThan": "10.22",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:thalesgroup:sentinel_ldk_runtime:*:*:windows:*:*:*:*:*",
                      "versionEndExcluding": "10.22",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Josh Dillon"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027) vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.\u003cp\u003eThis issue affects Sentinel LDK Runtime: before 10.22.\u003c/p\u003e"
                }
              ],
              "value": "Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027) vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.\n\nThis issue affects Sentinel LDK Runtime: before 10.22."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-592",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-592 Stored XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:44:12.227Z",
            "orgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
            "shortName": "THA-PSIRT"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.thalesgroup.com/csm?id=kb_article_view\u0026sys_kb_id=5c18186b478aa950128dca72e36d4391\u0026sysparm_article=KB0027106"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade current Sentinel\nLDK Runtime to version 10.22 or higher."
                }
              ],
              "value": "Upgrade current Sentinel\nLDK Runtime to version 10.22 or higher."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Stored XSS vulnerability in Sentinel ACC",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
        "assignerShortName": "THA-PSIRT",
        "cveId": "CVE-2026-3457",
        "datePublished": "2026-03-27T09:05:48.226Z",
        "dateReserved": "2026-03-02T19:33:17.694Z",
        "dateUpdated": "2026-09-03T15:44:12.227Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-0872 (GCVE-0-2026-0872)

    Vulnerability from cvelistv5 โ€“ Published: 2026-02-13 08:53 โ€“ Updated: 2026-09-03 15:59
    VLAI
    Title
    Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon
    Summary
    Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-02-13 12:47 UTC
    CWE
    • CWE-295 - Improper Certificate Validation
    Impacted products
    Vendor Product Version
    Thalesgroup SafeNet Agent for Windows Logon Affected: 4.0.0
    Affected: 4.1.1
    Affected: 4.1.2
        cpe:2.3:a:thalesgroup:safenet_agent_for_windows_logon:4.0.0:*:windows:*:*:*:*:*
        cpe:2.3:a:thalesgroup:safenet_agent_for_windows_logon:4.1.1:*:windows:*:*:*:*:*
        cpe:2.3:a:thalesgroup:safenet_agent_for_windows_logon:4.1.2:*:windows:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-02-08 08:52
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-0872",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-13T12:47:11.793545Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-13T12:47:30.747Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "SafeNet Agent for Windows Logon",
              "vendor": "Thalesgroup",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.0.0"
                },
                {
                  "status": "affected",
                  "version": "4.1.1"
                },
                {
                  "status": "affected",
                  "version": "4.1.2"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:thalesgroup:safenet_agent_for_windows_logon:4.0.0:*:windows:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:thalesgroup:safenet_agent_for_windows_logon:4.1.1:*:windows:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:thalesgroup:safenet_agent_for_windows_logon:4.1.2:*:windows:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Huy Kha, Director of Security Research, and the team at Netwrix"
            }
          ],
          "datePublic": "2026-02-08T08:52:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.\u003cp\u003eThis issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.\u003c/p\u003e"
                }
              ],
              "value": "Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.\n\nThis issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-475",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-475 Signature Spoofing by Improper Validation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 2.5,
                "baseSeverity": "LOW",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T15:59:17.919Z",
            "orgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
            "shortName": "THA-PSIRT"
          },
          "references": [
            {
              "tags": [
                "mitigation"
              ],
              "url": "https://thalesdocs.com/sta/agents/wla-windows_logon/wla-preinstallation_passwordless/index.html"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.thalesgroup.com/csm?sys_kb_id=247fd4a42b4a7290061af3f5f291bff1\u0026id=kb_article_view\u0026sysparm_rank=1\u0026sysparm_tsqueryId=5ecb72c73b927610381ecfaf55e45a0b\u0026sysparm_article=KB0030173"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to version 4.1.3."
                }
              ],
              "value": "Upgrade to version 4.1.3."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
        "assignerShortName": "THA-PSIRT",
        "cveId": "CVE-2026-0872",
        "datePublished": "2026-02-13T08:53:05.621Z",
        "dateReserved": "2026-01-13T09:32:05.991Z",
        "dateUpdated": "2026-09-03T15:59:17.919Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-5264 (GCVE-0-2024-5264)

    Vulnerability from cvelistv5 โ€“ Published: 2024-05-23 08:40 โ€“ Updated: 2024-08-01 21:11
    VLAI
    Title
    Network Key Transfer with AES KHT vulnerability in Luna EFT
    Summary
    Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-06-12 20:41 UTC
    CWE
    • CWE-338 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
    Impacted products
    Vendor Product Version
    Thales Luna EFT Affected: 2.1.0
    Create a notification for this product.
    thalesgroup luna_eft Affected: 2.1 , โ‰ค * (custom)
        cpe:2.3:a:thalesgroup:luna_eft:2.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:thalesgroup:luna_eft:2.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "luna_eft",
                "vendor": "thalesgroup",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "2.1",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5264",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-12T20:41:30.681683Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-12T20:41:33.798Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:11:11.016Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.thalesgroup.com/csm?id=kb_article_view\u0026sys_kb_id=50da3cd9c302c218204e2a6ce00131b9\u0026sysparm_article=KB0028531"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Network Key Transfer with AES KHT"
              ],
              "platforms": [
                "Appliance"
              ],
              "product": "Luna EFT",
              "vendor": "Thales",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1.0"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Network Transfer with AES KHT"
                }
              ],
              "value": "Network Transfer with AES KHT"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cory Whitesell, Sr. Security Engineer, Transaction Network Services"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis"
                }
              ],
              "value": "Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-20",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-20 Encryption Brute Forcing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-338",
                  "description": "CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-23T08:40:56.239Z",
            "orgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
            "shortName": "THA-PSIRT"
          },
          "references": [
            {
              "url": "https://supportportal.thalesgroup.com/csm?id=kb_article_view\u0026sys_kb_id=50da3cd9c302c218204e2a6ce00131b9\u0026sysparm_article=KB0028531"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Network Key Transfer with AES KHT vulnerability in Luna EFT",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Disable functionality in the console - see linked bulletin"
                }
              ],
              "value": "Disable functionality in the console - see linked bulletin"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
        "assignerShortName": "THA-PSIRT",
        "cveId": "CVE-2024-5264",
        "datePublished": "2024-05-23T08:40:56.239Z",
        "dateReserved": "2024-05-23T08:39:05.391Z",
        "dateUpdated": "2024-08-01T21:11:11.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0197 (GCVE-0-2024-0197)

    Vulnerability from cvelistv5 โ€“ Published: 2024-02-27 12:48 โ€“ Updated: 2024-08-09 15:26
    VLAI
    Title
    Privilege Escalation in Thales SafeNet Sentinel HASP LDK
    Summary
    A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-08-01 17:56 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    Thales Sentinel HASP LDK Affected: 0 , < 9.16 (9.16)
    Create a notification for this product.
    thalesgroup safenet_sentinel_hasp Affected: 0 , < 9.16 (custom)
        cpe:2.3:a:thalesgroup:safenet_sentinel_hasp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    thalesgroup safenet_sentinel_ldk Affected: 0 , โ‰ค 9.16 (custom)
        cpe:2.3:a:thalesgroup:safenet_sentinel_ldk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-02-15 23:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:16.069Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.thalesgroup.com"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:thalesgroup:safenet_sentinel_hasp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "safenet_sentinel_hasp",
                "vendor": "thalesgroup",
                "versions": [
                  {
                    "lessThan": "9.16",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:thalesgroup:safenet_sentinel_ldk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "safenet_sentinel_ldk",
                "vendor": "thalesgroup",
                "versions": [
                  {
                    "lessThanOrEqual": "9.16",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0197",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-01T17:56:38.989974Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-09T15:26:44.274Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "Sentinel HASP LDK",
              "vendor": "Thales",
              "versions": [
                {
                  "lessThan": "9.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "9.16"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Julian Horoszkiewicz (Eviden Red Team)"
            }
          ],
          "datePublic": "2024-02-15T23:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.\n\n"
                }
              ],
              "value": "A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-27T12:48:13.263Z",
            "orgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
            "shortName": "THA-PSIRT"
          },
          "references": [
            {
              "url": "https://supportportal.thalesgroup.com"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to Thales Sentinel LDK version 9.16.\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to Thales Sentinel LDK version 9.16.\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Privilege Escalation in Thales SafeNet Sentinel HASP LDK",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
        "assignerShortName": "THA-PSIRT",
        "cveId": "CVE-2024-0197",
        "datePublished": "2024-02-27T12:48:13.263Z",
        "dateReserved": "2024-01-02T15:23:33.572Z",
        "dateUpdated": "2024-08-09T15:26:44.274Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-7016 (GCVE-0-2023-7016)

    Vulnerability from cvelistv5 โ€“ Published: 2024-02-27 10:45 โ€“ Updated: 2024-08-15 18:53
    VLAI
    Title
    Privilege Escalation in SafeNet Authentication Client
    Summary
    A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-02-27 15:17 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    Thales SafeNet Authentication Client Affected: 0 , < 10.8 (patch 10)
    Create a notification for this product.
    thalesgroup safenet_authentication_client Affected: 0 , < 10.8 (custom)
        cpe:2.3:a:thalesgroup:safenet_authentication_client:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-02-18 23:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:50:07.630Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.thalesgroup.com"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:thalesgroup:safenet_authentication_client:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "safenet_authentication_client",
                "vendor": "thalesgroup",
                "versions": [
                  {
                    "lessThan": "10.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-7016",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-27T15:17:31.490247Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-15T18:53:46.190Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "SafeNet Authentication Client",
              "vendor": "Thales",
              "versions": [
                {
                  "lessThan": "10.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch 10"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Kravets Vasiliy, xi-tauw@xi-tauw.info"
            }
          ],
          "datePublic": "2024-02-18T23:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access."
                }
              ],
              "value": "A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-27T10:45:28.333Z",
            "orgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
            "shortName": "THA-PSIRT"
          },
          "references": [
            {
              "url": "https://supportportal.thalesgroup.com"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to the current SafeNet Authentication Client 10.8 R10 (GA).\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to the current SafeNet Authentication Client 10.8 R10 (GA).\n"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Privilege Escalation in SafeNet Authentication Client ",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
        "assignerShortName": "THA-PSIRT",
        "cveId": "CVE-2023-7016",
        "datePublished": "2024-02-27T10:45:28.333Z",
        "dateReserved": "2023-12-20T15:48:00.568Z",
        "dateUpdated": "2024-08-15T18:53:46.190Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5993 (GCVE-0-2023-5993)

    Vulnerability from cvelistv5 โ€“ Published: 2024-02-27 10:42 โ€“ Updated: 2024-08-08 19:28
    VLAI
    Title
    Privilege Escalation in SafeNet Authentication Client Installer
    Summary
    A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-02-27 15:39 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    Thales SafeNet Authentication Client Affected: 0 , < 10.8 (patch 10)
    Create a notification for this product.
    thalesgroup safenet_authentication_client Affected: 0 , < 10.8 (custom)
        cpe:2.3:a:thalesgroup:safenet_authentication_client:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-02-18 23:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:14:25.122Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.thalesgroup.com"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:thalesgroup:safenet_authentication_client:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "safenet_authentication_client",
                "vendor": "thalesgroup",
                "versions": [
                  {
                    "lessThan": "10.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5993",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-27T15:39:53.382676Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-08T19:28:36.205Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "SafeNet Authentication Client",
              "vendor": "Thales",
              "versions": [
                {
                  "lessThan": "10.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "patch 10"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Kravets Vasiliy, xi-tauw@xi-tauw.info"
            }
          ],
          "datePublic": "2024-02-18T23:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access."
                }
              ],
              "value": "A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-27T10:42:08.287Z",
            "orgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
            "shortName": "THA-PSIRT"
          },
          "references": [
            {
              "url": "https://supportportal.thalesgroup.com"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to the current SafeNet Authentication Client 10.8 R10 (GA)."
                }
              ],
              "value": "Upgrade to the current SafeNet Authentication Client 10.8 R10 (GA)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Privilege Escalation in SafeNet Authentication Client Installer",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9d5917ae-205d-4ae5-8749-1f49479b1395",
        "assignerShortName": "THA-PSIRT",
        "cveId": "CVE-2023-5993",
        "datePublished": "2024-02-27T10:42:08.287Z",
        "dateReserved": "2023-11-07T16:29:48.850Z",
        "dateUpdated": "2024-08-08T19:28:36.205Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }