Vulnerability Description
SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gemalto | Safenet Authentication Service Iis Agent | - |
Related Weaknesses (CWE)
References
- https://labs.nettitude.com/blog/cve-2015-7596-through-cve-2015-7598-cve-2015-796Third Party Advisory
- https://labs.nettitude.com/wp-content/uploads/2016/03/160125-1-Gemalto-IDSS-SecuPatchThird Party Advisory
- https://safenet.gemalto.com/technical-support/security-updates/Vendor Advisory
- https://labs.nettitude.com/blog/cve-2015-7596-through-cve-2015-7598-cve-2015-796Third Party Advisory
- https://labs.nettitude.com/wp-content/uploads/2016/03/160125-1-Gemalto-IDSS-SecuPatchThird Party Advisory
- https://safenet.gemalto.com/technical-support/security-updates/Vendor Advisory
FAQ
What is CVE-2015-7597?
CVE-2015-7597 is a vulnerability with a CVSS score of 7.8 (HIGH). SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
How severe is CVE-2015-7597?
CVE-2015-7597 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7597?
Check the references section above for vendor advisories and patch information. Affected products include: Gemalto Safenet Authentication Service Iis Agent.