Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one.
References
Configurations
Information
Published : 2019-06-07 08:29
Updated : 2020-10-22 10:19
NVD link : CVE-2019-8282
Mitre link : CVE-2019-8282
JSON object : View
CWE
CWE-346
Origin Validation Error
Products Affected
gemalto
- sentinel_ldk