Vulnerability record · CVE-2005-0353 · published 2 May 2005
CVE-2005-0353: Sentinel License Manager UDP buffer overflow allows remote code execution
Safenet · Sentinel License Manager
The Sentinel LM (Lservnt) service in Sentinel License Manager 7.2.0.2 contains a buffer overflow reachable by sending a large amount of data to UDP port 5093. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host running the license manager. Because the service is a licensing component, compromise can affect the availability and integrity of the software it licenses.
Description
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network-reachable, unauthenticated remote code execution and public exploit references makes this a maximum-severity issue for any exposed Sentinel License Manager 7.2.0.2 host.
What it is
The Sentinel LM (Lservnt) service in Sentinel License Manager 7.2.0.2 contains a buffer overflow reachable by sending a large amount of data to UDP port 5093. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host running the license manager. Because the service is a licensing component, compromise can affect the availability and integrity of the software it licenses.
Impact
An attacker gains remote code execution with the privileges of the Lservnt service, which typically runs with system-level rights. This allows full control of the affected host, including data theft, service disruption, and use as a pivot point.
Attack surface
The flaw is reached over the network via UDP port 5093 with no authentication required, as indicated by the CVSS vector AV:N/AC:L/Au:N. No user interaction is needed; a single crafted datagram is sufficient.
Exploitation
The record is not listed in CISA KEV, but EPSS is 0.7113 (99.376th percentile), indicating a high likelihood of exploitation activity. Multiple references are tagged Exploit, and a public advisory (CIRT-30) is tagged Exploit, so public exploit code appears to exist.
What to do
- Apply the vendor patch referenced in the Secunia, CIRT, and CERT/CC advisories as soon as possible.
- If patching is not immediately possible, block or restrict UDP port 5093 at network boundaries and host firewalls to trusted license clients only.
- Isolate license manager hosts on a dedicated management segment with no direct internet exposure.
- Monitor vendor advisories for updated Sentinel License Manager versions and upgrade beyond 7.2.0.2.
- Run the Lservnt service with the least privileges necessary rather than system-level rights where the product allows it.
Detection
- Monitor network traffic for unusually large or malformed UDP datagrams to port 5093.
- Alert on Lservnt process crashes or restarts, which may indicate a failed overflow attempt.
- Use IDS/IPS signatures for the known Sentinel LM UDP overflow pattern if available.
- Audit firewall logs for unexpected external hosts sending traffic to UDP 5093.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=111022094326772&w=2 | |
| http://marc.info/?l=full-disclosure&m=111072872816405&w=2 | |
| http://secunia.com/advisories/14511 | PatchVendor Advisory |
| http://www.cirt.dk/advisories/cirt-30-advisory.pdf | ExploitPatchVendor Advisory |
| http://www.kb.cert.org/vuls/id/108790 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/12742 | Exploit |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19621 | |
| http://marc.info/?l=bugtraq&m=111022094326772&w=2 | |
| http://marc.info/?l=full-disclosure&m=111072872816405&w=2 | |
| http://secunia.com/advisories/14511 | PatchVendor Advisory |
| http://www.cirt.dk/advisories/cirt-30-advisory.pdf | ExploitPatchVendor Advisory |
| http://www.kb.cert.org/vuls/id/108790 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/12742 | Exploit |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19621 |
Track CVE-2005-0353 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-0353), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.