VYPR

Network Security

by Stormshield

CVEs (39)

  • CVE-2023-34198HigFeb 29, 2024
    risk 0.47cvss 7.3epss 0.01

    In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in…

  • CVE-2021-28962HigJan 31, 2022
    risk 0.47cvss 7.2epss 0.01

    Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.

  • CVE-2023-47093MedDec 21, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine.

  • CVE-2021-37613MedFeb 10, 2022
    risk 0.42cvss 6.5epss 0.00

    Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.

  • CVE-2022-4304MedFeb 8, 2023
    risk 0.40cvss 5.9epss 0.16

    A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of…

  • CVE-2021-31814MedFeb 10, 2022
    risk 0.40cvss 6.1epss 0.00

    In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.

  • CVE-2020-8430MedApr 13, 2020
    risk 0.40cvss 6.1epss 0.01

    Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.

  • CVE-2021-3398MedFeb 10, 2022
    risk 0.38cvss 5.8epss 0.01

    Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.

  • CVE-2022-22703MedJan 17, 2022
    risk 0.36cvss 5.5epss 0.00

    In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.

  • CVE-2021-27506MedMar 19, 2021
    risk 0.36cvss 5.5epss 0.01

    The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19,…

  • CVE-2023-20052MedMar 1, 2023
    risk 0.35cvss 5.3epss 0.07

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access…

  • CVE-2021-28096MedJan 27, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.

  • CVE-2021-3384MedMar 2, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to…

  • CVE-2026-8474MedJun 1, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the…

  • CVE-2023-41166MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access…

  • CVE-2023-41165MedFeb 29, 2024
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a…

  • CVE-2020-11711MedAug 25, 2023
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin…

  • CVE-2026-8482MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone…

  • CVE-2026-8480MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who…

Page 2 of 2