PT-2021-19976 · Thales · Sentinel Ldk Run-Time Environment
Published
2021-06-16
·
Updated
2021-07-01
·
CVE-2021-32928
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sentinel LDK Run-Time Environment versions 7.6 and prior
Description
The issue arises from the Sentinel LDK Run-Time Environment installer, which adds a firewall rule named "Sentinel License Manager" allowing incoming connections from private networks using TCP Port 1947. During uninstallation, the uninstaller fails to close Port 1947, potentially leaving it open.
Recommendations
For versions 7.6 and prior, manually close TCP Port 1947 after uninstalling the Sentinel LDK Run-Time Environment to prevent potential exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentinel Ldk Run-Time Environment