SNS
by Stormshield
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30279 | Hig | 0.49 | 7.5 | 0.01 | May 12, 2022 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus… | ||
| CVE-2021-28127 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2021 | An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur. | ||
| CVE-2021-28665 | Hig | 0.49 | 7.5 | 0.01 | May 6, 2021 | Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service. | ||
| CVE-2021-28096 | Med | 0.35 | 5.3 | 0.01 | Jan 27, 2022 | An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections. | ||
| CVE-2020-11711 | Med | 0.31 | 4.8 | 0.00 | Aug 25, 2023 | An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin… |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
- risk 0.49cvss 7.5epss 0.01
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.
- risk 0.31cvss 4.8epss 0.00
An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin…