HIGH
Privilege Escalation in Thales SafeNet Sentinel HASP LDK
Published Feb 27, 2024
7.8
HIGHCVSS 3.1
EPSS 0.43%
Description
A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
Affected products
-
- Version 0StatusaffectedConstraints<9.16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Thales | Sentinel HASP LDK | unaffected |
|
AND
- < 9.16
-
- Version 0StatusaffectedConstraints<9.16
- Version
-
- Version 0StatusaffectedConstraints<=9.16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Thalesgroup | Safenet Sentinel Hasp | n/a |
| ||||||
| Thalesgroup | Safenet Sentinel Ldk | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to Thales Sentinel LDK version 9.16.
Weaknesses (1)
References (1)
| Link | Providers | Tags |
|---|---|---|
| https://supportportal.thalesgroup.com | Product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner THA-PSIRT
Published Feb 27, 2024
Updated Aug 9, 2024
Reserved Jan 2, 2024
Link CVE-2024-0197
CISA Vulnrichment
Updated Aug 1, 2024