Skip to main content

Vendor/product archive

stormshield / stormshield_network_security CVEs

Beta · best-effort

33 CVEs tagged to stormshield / stormshield_network_security4 Critical, 16 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2025-48707

Published Sep 25, 2025

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41165

Published Feb 29, 2024

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34198

Published Feb 29, 2024

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28616

Published Dec 26, 2023

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the passw…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47091

Published Dec 25, 2023

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47093

Published Dec 21, 2023

An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ en…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41166

Published Dec 21, 2023

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It'…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11711

Published Aug 25, 2023

An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27812

Published Aug 24, 2022

Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30279

Published May 12, 2022

An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23989

Published Mar 15, 2022

In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31617

Published Jan 31, 2022

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-28096

Published Jan 27, 2022

An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any n…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2