Gemalto develops software-licensing, authentication, and identity-management solutions that serve enterprise and financial sectors, with a relatively focused but security-sensitive product portfolio including Sentinel licensing infrastructure, SafeNet authentication platforms, and EZIO credential-management servers. The vendor's vulnerabilities skew toward serious outcomes across a meaningful share reaching critical severity, reflecting the trust-critical role these products play in access control and key management. Recurring weakness classes center on memory-safety issues such as buffer-overflow conditions, authentication and session-handling flaws including capture-replay and bypass mechanisms, and improper access controls—patterns that matter because these products often sit between users and high-value protected resources. Defenders should treat vulnerabilities in this vendor's licensing and authentication products as high-priority, particularly in environments where these services guard sensitive credential issuance or software entitlements. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gemalto over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6953HIGH Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution | May 8, 2017 | 7.8 | 35 | NO | YES |
CVE-2017-11497CRITICAL Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary c | Oct 3, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-11496CRITICAL Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary c | Oct 3, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-9156HIGH Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection. | Jun 5, 2019 | 8.0 | 26 | NO | NO |
CVE-2018-15492HIGH A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification. | Aug 18, 2018 | 7.5 | 25 | NO | NO |
CVE-2017-11498HIGH Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote proc | Oct 3, 2017 | 7.5 | 25 | NO | NO |
CVE-2015-7962HIGH SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privilege | Mar 2, 2018 | 7.8 | 24 | NO | NO |
CVE-2019-18232HIGH SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may a | Dec 11, 2019 | 7.8 | 23 | NO | NO |
CVE-2018-6305HIGH Denial of service in Gemalto's Sentinel LDK RTE version before 7.65 | Mar 13, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-6304HIGH Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service | Mar 13, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gemalto.
Media articles that mention a CVE ID that affects a product developed by Gemalto — matched by CVE ID, not by vendor name.