Thalesgroup kayıtları
thalesgroup üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %23,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-269 Improper Privilege Management3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-284 Improper Access Control1
- CWE-331 Insufficient Entropy1
- CWE-336 Same Seed in Pseudo-Random Number Generator (PRNG)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-32928İstismar yok | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows ithalesgroup · sentinel ldk run-time environment · CWE-459 | Kritik9,8 | — | %1,3 | 16 Haz 2021 |
31İzleyin | CVE-2024-0197Kavram kanıtı | Privilege Escalation in Thales SafeNet Sentinel HASP LDKthalesgroup · sentinel hasp ldk · CWE-269 | Yüksek7,8 | — | %0,4 | 27 Şub 2024 |
31İzleyin | CVE-2023-7016Kavram kanıtı | Privilege Escalation in SafeNet Authentication Clientthalesgroup · safenet authentication client · CWE-269 | Yüksek7,8 | — | %0,3 | 27 Şub 2024 |
31İzleyin | CVE-2021-42810İstismar yok | Safenet Authentication Service Remote Desktop Gateway prior to 2.0.3 may allow privilege escilation to authenticated usersthalesgroup · safenet authentication service remote desktop gateway · CWE-336 | Yüksek7,8 | — | %0,3 | 19 Oca 2022 |
31İzleyin | CVE-2021-42809İstismar yok | The Sentinel Protection Installer 7.7.0 does not properly restrict loading Dynamic Link Librarythalesgroup · sentinel protection installer · CWE-913 | Yüksek7,8 | — | %0,3 | 20 Ara 2021 |
31İzleyin | CVE-2023-5993İstismar yok | Privilege Escalation in SafeNet Authentication Client Installerthalesgroup · safenet authentication client · CWE-269 | Yüksek7,8 | — | %0,2 | 27 Şub 2024 |
27İzleyin | CVE-2026-6805İstismar yok | Vulnerability on Cryptobox external sharing featurethalesgroup · ercom cryptobox · CWE-280 | Orta6,9 | — | %0,4 | 7 May 2026 |
26İzleyin | CVE-2021-28979İstismar yok | SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks.thalesgroup · safenet keysecure · CWE-74 | Orta6,5 | — | %1,2 | 16 Haz 2021 |
26İzleyin | CVE-2021-42056Kavram kanıtı | Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a loclinux · linux kernel · CWE-59 | Orta6,7 | — | %1,0 | 24 Haz 2022 |
26İzleyin | CVE-2021-42138İstismar yok | A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or allthalesgroup · safenet windows logon agent · CWE-331 | Orta6,5 | — | %0,6 | 20 Ara 2021 |
26İzleyin | CVE-2021-42811İstismar yok | Vulnerability in SafeNet KeySecurethalesgroup · safenet keysecure · CWE-22 | Orta6,5 | — | %0,5 | 10 Haz 2022 |
26İzleyin | CVE-2024-5264İstismar yok | Network Key Transfer with AES KHT vulnerability in Luna EFTthalesgroup · luna eft · CWE-338 | Orta6,5 | — | %0,4 | 23 May 2024 |
26İzleyin | CVE-2021-42808İstismar yok | The Sentinel Protection Installer 7.7.0 creates files and directory with all privileges granting any user full permissions.thalesgroup · sentinel protection installer · CWE-284 | Orta6,7 | — | %0,2 | 20 Ara 2021 |
25İzleyin | CVE-2020-15858İstismar yok | Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers.thalesgroup · bgs5 firmware · CWE-22 | Orta6,4 | — | %0,8 | 21 Ağu 2020 |
24İzleyin | CVE-2022-1293İstismar yok | XSS vulnerability in Citadelthalesgroup · citadel · CWE-80 | Orta6,1 | — | %0,5 | 2 Ağu 2022 |
22İzleyin | CVE-2023-2737İstismar yok | Improper securing of log directory may allow a denial of servicethalesgroup · safenet authentication service · CWE-276 | Orta5,5 | — | %0,1 | 16 Ağu 2023 |
18İzleyin | CVE-2019-15809İstismar yok | Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in Emicrochip · atmel toolbox · CWE-203 | Orta4,7 | — | %0,5 | 3 Eki 2019 |
- CVE-2021-3292839İzleyin
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i
KritikCVSS 9,8İstismar yokEPSS %1thalesgroup · sentinel ldk run-time environment16 Haz 2021
- CVE-2024-019731İzleyin
Privilege Escalation in Thales SafeNet Sentinel HASP LDK
YüksekCVSS 7,8Kavram kanıtıEPSS %0thalesgroup · sentinel hasp ldk27 Şub 2024
- CVE-2023-701631İzleyin
Privilege Escalation in SafeNet Authentication Client
YüksekCVSS 7,8Kavram kanıtıEPSS %0thalesgroup · safenet authentication client27 Şub 2024
- CVE-2021-4281031İzleyin
Safenet Authentication Service Remote Desktop Gateway prior to 2.0.3 may allow privilege escilation to authenticated users
YüksekCVSS 7,8İstismar yokEPSS %0thalesgroup · safenet authentication service remote desktop gateway19 Oca 2022
- CVE-2021-4280931İzleyin
The Sentinel Protection Installer 7.7.0 does not properly restrict loading Dynamic Link Library
YüksekCVSS 7,8İstismar yokEPSS %0thalesgroup · sentinel protection installer20 Ara 2021
- CVE-2023-599331İzleyin
Privilege Escalation in SafeNet Authentication Client Installer
YüksekCVSS 7,8İstismar yokEPSS %0thalesgroup · safenet authentication client27 Şub 2024
- CVE-2026-680527İzleyin
Vulnerability on Cryptobox external sharing feature
OrtaCVSS 6,9İstismar yokEPSS %0thalesgroup · ercom cryptobox7 May 2026
- CVE-2021-2897926İzleyin
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks.
OrtaCVSS 6,5İstismar yokEPSS %1thalesgroup · safenet keysecure16 Haz 2021
- CVE-2021-4205626İzleyin
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a loc
OrtaCVSS 6,7Kavram kanıtıEPSS %1linux · linux kernel24 Haz 2022
- CVE-2021-4213826İzleyin
A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all
OrtaCVSS 6,5İstismar yokEPSS %1thalesgroup · safenet windows logon agent20 Ara 2021
- CVE-2021-4281126İzleyin
Vulnerability in SafeNet KeySecure
OrtaCVSS 6,5İstismar yokEPSS %1thalesgroup · safenet keysecure10 Haz 2022
- CVE-2024-526426İzleyin
Network Key Transfer with AES KHT vulnerability in Luna EFT
OrtaCVSS 6,5İstismar yokEPSS %0thalesgroup · luna eft23 May 2024
- CVE-2021-4280826İzleyin
The Sentinel Protection Installer 7.7.0 creates files and directory with all privileges granting any user full permissions.
OrtaCVSS 6,7İstismar yokEPSS %0thalesgroup · sentinel protection installer20 Ara 2021
- CVE-2020-1585825İzleyin
Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers.
OrtaCVSS 6,4İstismar yokEPSS %1thalesgroup · bgs5 firmware21 Ağu 2020
- CVE-2022-129324İzleyin
XSS vulnerability in Citadel
OrtaCVSS 6,1İstismar yokEPSS %0thalesgroup · citadel2 Ağu 2022
- CVE-2023-273722İzleyin
Improper securing of log directory may allow a denial of service
OrtaCVSS 5,5İstismar yokEPSS %0thalesgroup · safenet authentication service16 Ağu 2023
- CVE-2019-1580918İzleyin
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in E
OrtaCVSS 4,7İstismar yokEPSS %0microchip · atmel toolbox3 Eki 2019