VYPR

Network Security

by Stormshield

CVEs (6)

  • CVE-2021-45885HigDec 29, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

  • CVE-2021-28665HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

  • CVE-2022-22703MedJan 17, 2022
    risk 0.36cvss 5.5epss 0.00

    In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.

  • CVE-2026-8474MedJun 1, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the…

  • CVE-2026-8482MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone…

  • CVE-2026-8480MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who…