Cautionary Advisory for SGA Solutions Products

Cautionary Advisory for SGA Solutions Products

Overview

 

We have released a security update to fix vulnerabilities in SGA Solutions products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

TrustPKI Enterprise version: 1.2.8.9 and earlier

 

 

Resolved Vulnerabilities

 

Remote code execution vulnerability due to unvalidation in SGA Solutions TrustPKI Enterprise
Arbitrary file download vulnerability due to lack of validation in SGA Solutions TrustPKI Enterprise

 

 

Vulnerability Patches

 

The product is discontinued (end of life), so if you have the affected product installed on your PC, please uninstall it immediately.

 

 

References

 

[1] SGA Solutions product advisories
https://www.krcert.or.kr/kr/bbs/view.do?searchCnd=&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=1&categoryCode=&nttId=71826