Vulnerabilities
Vulnerable Software
Stormshield:  Security Vulnerabilities
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
CVSS Score
5.2
EPSS Score
0.003
Published
2021-12-21
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
CVSS Score
9.8
EPSS Score
0.029
Published
2021-12-21
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
CVSS Score
4.3
EPSS Score
0.006
Published
2021-12-21
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
CVSS Score
7.5
EPSS Score
0.231
Published
2021-11-11
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
CVSS Score
5.2
EPSS Score
0.003
Published
2021-07-13
SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.
CVSS Score
5.7
EPSS Score
0.005
Published
2021-07-13
SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.
CVSS Score
5.7
EPSS Score
0.005
Published
2021-07-13
SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.
CVSS Score
5.7
EPSS Score
0.006
Published
2021-07-13
SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.
CVSS Score
3.5
EPSS Score
0.003
Published
2021-07-13
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
CVSS Score
6.7
EPSS Score
0.003
Published
2021-07-13


Contact Us

Shodan ® - All rights reserved