← Back

Stormshield

stormshield

59 CVEs • 6 products

Products (6)

Click to collapse
Toggle

CVEs (59)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Stormshield
1Endpoint Security
Jun 17, 2026
Dec 21, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
1Stormshield
1Endpoint Security
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
1Stormshield
1Endpoint Security
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.2 MEDIUM· v3
2.3 LOW· v2
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
6Balasys
F5Hpe+3 more
30Arubaos Cx
Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+27 more
Aug 22, 2025
Nov 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculati...Show more
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.Show less
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
3.5 LOW· v3
2.9 LOW· v2
SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
5.2 MEDIUM· v3
2.3 LOW· v2
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
1Stormshield
1Endpoint Security
Jun 17, 2026
Jul 13, 2021
N/A· v4
7.3 HIGH· v3
4.3 MEDIUM· v2
SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installed.
1Stormshield
1Stormshield Network Security
Jun 17, 2026
Jul 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
1Stormshield
2Network Security
Stormshield Network Security
Jun 17, 2026
May 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
3Clamav
Netasq ProjectStormshield
3Clamav
NetasqStormshield Network Security
Jun 17, 2026
Mar 19, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS ver...Show more
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.Show less
1Stormshield
1Stormshield Network Security
Jun 17, 2026
Mar 2, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This...Show more
A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.Show less
2Mpd Project
Stormshield
2Mpd
Stormshield Network Security
Jun 17, 2026
Oct 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of...Show more
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.Show less
2Mpd Project
Stormshield
2Mpd
Stormshield Network Security
Jun 17, 2026
Oct 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption...Show more
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).Show less
1Stormshield
1Stormshield Network Security
Jun 17, 2026
Apr 13, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in...Show more
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.Show less
1Stormshield
1Stormshield Network Security
Nov 21, 2024
Jul 4, 2019
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.