Stormshield
stormshield
59 CVEs • 6 products
Products (6)
Click to collapseToggle
Products (6)
Click to collapse
CVEs (59)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Stormshield 1Stormshield Network Security Jun 17, 2026 Sep 25, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing. |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Feb 29, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administ...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Feb 29, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Dec 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Dec 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Dec 21, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine. |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Dec 21, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user acc...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Aug 28, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet. |
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. |
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions. |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Aug 25, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file...Show more |
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine. |
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read d...Show more |
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges. |
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. |
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. |
3Cisco ClamavStormshield4Clamav Secure EndpointSecure Endpoint Private Cloud+1 moreJun 17, 2026 Mar 1, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier co...Show more |
3Cisco ClamavStormshield5Clamav Secure EndpointSecure Endpoint Private Cloud+2 moreJun 17, 2026 Mar 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and...Show more |
2Openssl Stormshield2Openssl Stormshield Management CenterJun 17, 2026 Feb 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation o...Show more |
2Openssl Stormshield3Openssl Stormshield Management CenterStormshield Network SecurityJun 17, 2026 Feb 8, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly spe...Show more |