Sentinel's vulnerability footprint centers on its LDK RTE firmware product, a narrowly scoped but prominently deployed component whose disclosures cluster around memory-safety and authentication issues including buffer-boundary violations, improper authentication mechanisms, and missing authentication enforcement on critical functions. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sentinel over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12821CRITICAL Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution. | Oct 4, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-12820HIGH Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of | Oct 4, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-12822CRITICAL Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors. | Oct 4, 2017 | 9.9 | 24 | NO | NO |
CVE-2017-12819CRITICAL Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE v | Oct 4, 2017 | 9.8 | 24 | NO | NO |
CVE-2017-12818HIGH Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service. | Oct 4, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sentinel.
Media articles that mention a CVE ID that affects a product developed by Sentinel — matched by CVE ID, not by vendor name.