CVE-2017-6953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
08/05/2017
Last modified:
20/04/2025

Description

Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted input to SmartDiag.exe or SymDiag.exe.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gemalto:smartdiag_diagnosis_tool:*:*:*:*:*:*:*:* 2.5 (including)