Cautionary Advisory for SGA Solutions Products
Overview
We have released a security update to fix vulnerabilities in SGA Solutions products. Users of affected products are advised to update to the latest version.
Affected Products
TrustPKI Enterprise version: 1.2.8.9 and earlier
Resolved Vulnerabilities
Remote code execution vulnerability due to unvalidation in SGA Solutions TrustPKI Enterprise
Arbitrary file download vulnerability due to lack of validation in SGA Solutions TrustPKI Enterprise
Vulnerability Patches
The product is discontinued (end of life), so if you have the affected product installed on your PC, please uninstall it immediately.
References
[1] SGA Solutions product advisories
https://www.krcert.or.kr/kr/bbs/view.do?searchCnd=&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=1&categoryCode=&nttId=71826