A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.
Solution:
A Pseudo-Random Number Generator (PRNG) uses the same seed each time the product is initialized.
The product uses a Pseudo-Random Number Generator (PRNG) but does not correctly manage seeds.
Link | Tags |
---|---|
https://cpl.thalesgroup.com/support/security-updates | release notes vendor advisory |
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0002/MNDT-2022-0002.md | third party advisory |