Vendor CVEs
Stormshield
All CVEs
66 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-8474 | Med | 0.34 | 5.3 | 0.00 | Jun 1, 2026 | A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the… | ||
| CVE-2023-41166 | Med | 0.34 | 5.3 | 0.00 | Dec 21, 2023 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access… | ||
| CVE-2022-46783 | Med | 0.34 | 5.3 | 0.00 | Aug 28, 2023 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. | ||
| CVE-2021-45089 | Med | 0.34 | 5.2 | 0.00 | Dec 21, 2021 | Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control. | ||
| CVE-2021-31220 | Med | 0.34 | 5.2 | 0.00 | Jul 13, 2021 | SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies. | ||
| CVE-2023-41165 | Med | 0.31 | 4.8 | 0.00 | Feb 29, 2024 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a… | ||
| CVE-2020-11711 | Med | 0.31 | 4.8 | 0.00 | Aug 25, 2023 | An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin… | ||
| CVE-2026-14466 | Med | 0.28 | 4.3 | 0.00 | Sep 4, 2026 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface. | ||
| CVE-2023-35800 | Med | 0.28 | 4.3 | 0.00 | Jun 27, 2023 | Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to… | ||
| CVE-2023-23562 | Med | 0.28 | 4.3 | 0.00 | May 31, 2023 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | ||
| CVE-2021-45091 | Med | 0.28 | 4.3 | 0.01 | Dec 21, 2021 | Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control. | ||
| CVE-2024-37386 | Med | 0.27 | 4.2 | 0.00 | Jul 15, 2024 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, 4.7.6, and 4.8.2. | ||
| CVE-2024-31946 | Med | 0.27 | 4.2 | 0.00 | Jul 15, 2024 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing… | ||
| CVE-2021-31224 | Low | 0.23 | 3.5 | 0.00 | Jul 13, 2021 | SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies. | ||
| CVE-2026-8482 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone… | ||
| CVE-2026-8480 | Med | 0.00 | 4.3 | 0.00 | Jul 1, 2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who… |
- risk 0.34cvss 5.3epss 0.00
A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.
- risk 0.34cvss 5.2epss 0.00
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
- risk 0.34cvss 5.2epss 0.00
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
- risk 0.31cvss 4.8epss 0.00
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a…
- risk 0.31cvss 4.8epss 0.00
An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin…
- risk 0.28cvss 4.3epss 0.00
It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
- risk 0.28cvss 4.3epss 0.00
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to…
- risk 0.28cvss 4.3epss 0.00
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.
- risk 0.28cvss 4.3epss 0.01
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, 4.7.6, and 4.8.2.
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing…
- risk 0.23cvss 3.5epss 0.00
SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.
- risk 0.00cvss 4.3epss 0.00
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who…
Page 2 of 2