VYPR

Vendor CVEs

Stormshield

All CVEs

66 total · sorted by risk
  • CVE-2026-8474MedJun 1, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the…

  • CVE-2023-41166MedDec 21, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access…

  • CVE-2022-46783MedAug 28, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.

  • CVE-2021-45089MedDec 21, 2021
    risk 0.34cvss 5.2epss 0.00

    Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.

  • CVE-2021-31220MedJul 13, 2021
    risk 0.34cvss 5.2epss 0.00

    SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.

  • CVE-2023-41165MedFeb 29, 2024
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a…

  • CVE-2020-11711MedAug 25, 2023
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin…

  • CVE-2026-14466MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.

  • CVE-2023-35800MedJun 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to…

  • CVE-2023-23562MedMay 31, 2023
    risk 0.28cvss 4.3epss 0.00

    Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.

  • CVE-2021-45091MedDec 21, 2021
    risk 0.28cvss 4.3epss 0.01

    Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.

  • CVE-2024-37386MedJul 15, 2024
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, 4.7.6, and 4.8.2.

  • CVE-2024-31946MedJul 15, 2024
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing…

  • CVE-2021-31224LowJul 13, 2021
    risk 0.23cvss 3.5epss 0.00

    SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

  • CVE-2026-8482MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone…

  • CVE-2026-8480MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who…

Page 2 of 2