CVE-2021-32928
Thales Sentinel Runtime vulnerability analysis and mitigation

Overview

The Sentinel LDK Run-Time Environment (RTE) installer versions 7.6 and prior contains a vulnerability identified as CVE-2021-32928. The vulnerability was discovered and disclosed in June 2021, affecting systems with the Sentinel License Manager firewall rule. This vulnerability impacts multiple vendors' products that utilize the Thales Sentinel LDK Run-Time Environment (CISA Advisory).

Technical details

The vulnerability stems from an incomplete cleanup process during software uninstallation. The run-time environment installer adds a firewall rule named 'Sentinel License Manager' that allows incoming connections from private networks using TCP Port 1947. The critical security flaw occurs when uninstalling the software, as the uninstaller fails to close Port 1947, leaving it exposed. The vulnerability has been assigned a CVSS v3 base score of 9.6 with the vector string (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), indicating its critical severity (CISA Advisory).

Impact

The vulnerability leaves TCP Port 1947 open after uninstallation, potentially allowing attackers to connect to affected systems. This exposure could lead to unauthorized access to systems that previously had the Sentinel LDK Run-Time Environment installed and then uninstalled (CISA Advisory).

Mitigation and workarounds

Thales recommends upgrading to RTE Version 8.15 or later. For systems where uninstallation is necessary with affected versions, users should select the 'purge option' during uninstallation, which removes the Sentinel License Manager and closes the port. For already affected systems, administrators should ensure TCP Port 1947 is closed and implement appropriate IDS/IPS measures against this port. Additionally, CISA recommends minimizing network exposure for all control system devices and ensuring they are not accessible from the Internet (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management