Safenet's vulnerability footprint is concentrated in a small set of remote-access and cryptographic-key management products that serve specialized enterprise security roles, including VPN clients, high-assurance remote platforms, and key protection servers. Its disclosures recur around path-traversal weaknesses and unclassified issues reflective of the file-system and access-control surface inherent to local security software, and have a pronounced tendency toward public exploit availability. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Safenet over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1943HIGH Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 625 | Jun 5, 2009 | 10.0 | 83 | NO | YES |
CVE-2005-0353HIGH Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to | May 2, 2005 | 10.0 | 80 | NO | YES |
CVE-2009-3861MEDIUM Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via | Nov 4, 2009 | 6.9 | 39 | NO | YES |
CVE-2007-6483MEDIUM Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versi | Dec 20, 2007 | 5.0 | 29 | NO | YES |
CVE-2008-5121HIGH dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and | Nov 18, 2008 | 7.2 | 27 | NO | YES |
CVE-2008-0573HIGH IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request. | Feb 5, 2008 | 7.2 | 27 | NO | YES |
CVE-2007-3157MEDIUM IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an | Jun 11, 2007 | 5.0 | 27 | NO | YES |
CVE-2014-5359HIGH Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary | Dec 16, 2014 | 7.8 | 26 | NO | NO |
CVE-2008-0760MEDIUM Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary | Feb 13, 2008 | 5.0 | 25 | NO | YES |
CVE-2014-5872MEDIUM The SafeNetMobile Pass (aka securecomputing.devices.android.controller) application 8.3.7.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-th | Sep 11, 2014 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Safenet.
Media articles that mention a CVE ID that affects a product developed by Safenet — matched by CVE ID, not by vendor name.