Skip to main content

Vendor/product archive

stormshield / endpoint_security CVEs

Beta · best-effort

15 CVEs tagged to stormshield / endpoint_security1 Critical, 1 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2023-35800

Published Jun 27, 2023

Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35799

Published Jun 27, 2023

Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local syst…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23562

Published May 31, 2023

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23561

Published May 30, 2023

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35957

Published Jul 13, 2021

Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31224

Published Jul 13, 2021

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-31223

Published Jul 13, 2021

SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31222

Published Jul 13, 2021

SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31221

Published Jul 13, 2021

SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31220

Published Jul 13, 2021

SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31225

Published Jul 13, 2021

SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installe…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1