Skip to main content

Vendor archive

stormshield CVEs

Beta · best-effort

58 CVEs tagged to vendor stormshield5 Critical, 23 High, 29 Medium, 1 Low, 0 Unrated.

CVE-2025-48707

Published Sep 25, 2025

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41165

Published Feb 29, 2024

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34198

Published Feb 29, 2024

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28616

Published Dec 26, 2023

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the passw…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47091

Published Dec 25, 2023

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47093

Published Dec 21, 2023

An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ en…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41166

Published Dec 21, 2023

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It'…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46783

Published Aug 28, 2023

An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27932

Published Aug 25, 2023

Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11711

Published Aug 25, 2023

An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46782

Published Aug 5, 2023

An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35800

Published Jun 27, 2023

Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35799

Published Jun 27, 2023

Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local syst…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23562

Published May 31, 2023

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23561

Published May 30, 2023

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 58 CVEsPage 1 of 3