VYPR

Network Security

by Stormshield

CVEs (39)

  • CVE-2023-20032CriMar 1, 2023
    risk 0.66cvss 9.8epss 0.29

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to…

  • CVE-2022-37434CriAug 5, 2022
    risk 0.65cvss 9.8epss 0.18

    zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable…

  • CVE-2021-31617CriJan 31, 2022
    risk 0.64cvss 9.8epss 0.02

    In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.

  • CVE-2020-7465CriOct 6, 2020
    risk 0.64cvss 9.8epss 0.03

    The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).

  • CVE-2023-0286HigFeb 8, 2023
    risk 0.53cvss 7.4epss 0.59

    There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This…

  • CVE-2018-20850HigJul 4, 2019
    risk 0.53cvss 8.2epss 0.00

    Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.

  • CVE-2002-20001HigNov 11, 2021
    risk 0.51cvss 7.5epss 0.25

    The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs…

  • CVE-2022-4450HigFeb 8, 2023
    risk 0.50cvss 7.5epss 0.20

    The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing…

  • CVE-2025-48707HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.

  • CVE-2023-28616HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and…

  • CVE-2023-47091HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.

  • CVE-2023-26095HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.

  • CVE-2022-40617HigOct 31, 2022
    risk 0.49cvss 7.5epss 0.02

    strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly…

  • CVE-2022-27812HigAug 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS.

  • CVE-2022-30279HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus…

  • CVE-2022-23989HigMar 15, 2022
    risk 0.49cvss 7.5epss 0.01

    In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface. This could result in the blocking of almost all…

  • CVE-2021-45885HigDec 29, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

  • CVE-2021-28127HigJul 1, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

  • CVE-2021-28665HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

  • CVE-2020-7466HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.02

    The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.

Page 1 of 2