Skip to main content

Vendor archive

stormshield CVEs

Beta · best-effort

58 CVEs tagged to vendor stormshield5 Critical, 23 High, 29 Medium, 1 Low, 0 Unrated.

CVE-2022-27812

Published Aug 24, 2022

Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30279

Published May 12, 2022

An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23989

Published Mar 15, 2022

In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31617

Published Jan 31, 2022

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-28096

Published Jan 27, 2022

An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any n…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45885

Published Dec 29, 2021

An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35957

Published Jul 13, 2021

Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31224

Published Jul 13, 2021

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-31223

Published Jul 13, 2021

SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31222

Published Jul 13, 2021

SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31221

Published Jul 13, 2021

SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31220

Published Jul 13, 2021

SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31225

Published Jul 13, 2021

SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installe…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 58 CVEsPage 2 of 3