SSL VPN Client
by Stormshield
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27932 | Hig | 0.51 | 7.8 | 0.00 | Aug 25, 2023 | Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions. | ||
| CVE-2022-46782 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2023 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine. | ||
| CVE-2021-31814 | Med | 0.40 | 6.1 | 0.00 | Feb 10, 2022 | In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client. | ||
| CVE-2022-46783 | Med | 0.34 | 5.3 | 0.00 | Aug 28, 2023 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. |
- risk 0.51cvss 7.8epss 0.00
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.
- risk 0.40cvss 6.1epss 0.00
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.