Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gemalto

First CVE: Jul 22, 2015Active for: 11 yearsTotal CVEs: 26
43.1
VTI Score
High

Gemalto develops software-licensing, authentication, and identity-management solutions that serve enterprise and financial sectors, with a relatively focused but security-sensitive product portfolio including Sentinel licensing infrastructure, SafeNet authentication platforms, and EZIO credential-management servers. The vendor's vulnerabilities skew toward serious outcomes across a meaningful share reaching critical severity, reflecting the trust-critical role these products play in access control and key management. Recurring weakness classes center on memory-safety issues such as buffer-overflow conditions, authentication and session-handling flaws including capture-replay and bypass mechanisms, and improper access controls—patterns that matter because these products often sit between users and high-value protected resources. Defenders should treat vulnerabilities in this vendor's licensing and authentication products as high-priority, particularly in environments where these services guard sensitive credential issuance or software entitlements. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gemalto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2015
11 years ago
Most Recent CVE
Dec 11, 2019
2,419 days ago

Products(19 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-6953HIGH
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution
May 8, 20177.835NOYES
CVE-2017-11497CRITICAL
Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary c
Oct 3, 20179.832NONO
CVE-2017-11496CRITICAL
Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary c
Oct 3, 20179.832NONO
CVE-2019-9156HIGH
Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
Jun 5, 20198.026NONO
CVE-2018-15492HIGH
A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.
Aug 18, 20187.525NONO
CVE-2017-11498HIGH
Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote proc
Oct 3, 20177.525NONO
CVE-2015-7962HIGH
SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privilege
Mar 2, 20187.824NONO
CVE-2019-18232HIGH
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may a
Dec 11, 20197.823NONO
CVE-2018-6305HIGH
Denial of service in Gemalto's Sentinel LDK RTE version before 7.65
Mar 13, 20187.523NONO
CVE-2018-6304HIGH
Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service
Mar 13, 20187.523NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
19%
69%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (50.0%)
Network9 (34.6%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network3 (11.5%)
Attack Complexity
Low24 (92.3%)
High1 (3.8%)
Unknown1 (3.8%)
User Interaction
None21 (80.8%)
Unknown1 (3.8%)
Required4 (15.4%)
Privileges Required
Low15 (57.7%)
High0 (0.0%)
None10 (38.5%)
Unknown1 (3.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gemalto.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gemalto — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gemalto's Products

View all 3 CNAs →

Top CWEs