Vulnerabilities
Vulnerable Software
Stormshield:  Security Vulnerabilities
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash.
CVSS Score
7.5
EPSS Score
0.009
Published
2022-05-12
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface. This could result in the blocking of almost all network traffic, making the firewall unreachable. An attacker could exploit this via forged and properly timed traffic to cause a denial of service.
CVSS Score
7.5
EPSS Score
0.009
Published
2022-03-15
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.
CVSS Score
6.1
EPSS Score
0.002
Published
2022-02-10
Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.
CVSS Score
6.5
EPSS Score
0.004
Published
2022-02-10
Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.
CVSS Score
5.8
EPSS Score
0.009
Published
2022-02-10
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.
CVSS Score
9.8
EPSS Score
0.021
Published
2022-01-31
Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.
CVSS Score
7.2
EPSS Score
0.012
Published
2022-01-31
An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.
CVSS Score
5.3
EPSS Score
0.009
Published
2022-01-27
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
CVSS Score
5.5
EPSS Score
0.002
Published
2022-01-17
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.
CVSS Score
7.5
EPSS Score
0.009
Published
2021-12-29


Contact Us

Shodan ® - All rights reserved