Stormshield
Stormshield Network Security: vulnerabilidades y CVE
Stormshield Network Security tiene 40 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses3
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8482 | Media (4.3) | 0.23% | — | 2 jul 2026 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands… |
| CVE-2026-8480 | Media (4.3) | 0.13% | — | 1 jul 2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the… |
| CVE-2026-8474 | Media (5.3) | 0.30% | — | 1 jun 2026 | A vulnerability was discovered on Stormshield Network Security It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The… |
| CVE-2025-48707 | Alta (7.5) | 0.34% | — | 25 sept 2025 | An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing. |
| CVE-2025-27829 | Alta (7.3) | 0.29% | — | 1 abr 2025 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces.… |
| CVE-2024-37386 | Media (4.2) | 0.20% | — | 15 jul 2024 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The… |
| CVE-2024-31946 | Media (4.2) | 0.17% | — | 15 jul 2024 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email… |
| CVE-2023-41165 | Media (4.8) | 0.41% | — | 29 feb 2024 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An… |
| CVE-2023-34198 | Alta (7.3) | 0.51% | — | 29 feb 2024 | In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of… |
| CVE-2023-28616 | Alta (7.5) | 0.29% | — | 26 dic 2023 | An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space… |
| CVE-2023-47091 | Alta (7.5) | 0.53% | — | 25 dic 2023 | An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie… |
| CVE-2023-47093 | Media (6.5) | 0.29% | — | 21 dic 2023 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine. |
| CVE-2023-41166 | Media (5.3) | 0.40% | — | 21 dic 2023 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user… |
| CVE-2023-26095 | Alta (7.5) | 0.62% | — | 28 ago 2023 | ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet. |
| CVE-2020-11711 | Media (4.8) | 0.47% | — | 25 ago 2023 | An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file… |
| CVE-2023-20052 | Media (5.3) | 7.0% | — | 1 mar 2023 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could… |
| CVE-2023-20032 | Crítica (9.8) | 29% | — | 1 mar 2023 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and… |
| CVE-2023-0286 | Alta (7.4) | 60% | — | 8 feb 2023 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly… |
| CVE-2022-4450 | Alta (7.5) | 20% | — | 8 feb 2023 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data"… |
| CVE-2022-4304 | Media (5.9) | 16% | — | 8 feb 2023 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an… |
| CVE-2022-40617 | Alta (7.5) | 1.7% | — | 31 oct 2022 | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a… |
| CVE-2022-27812 | Alta (7.5) | 0.75% | — | 24 ago 2022 | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS. |
| CVE-2022-37434 | Crítica (9.8) | 19% | — | 5 ago 2022 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common… |
| CVE-2022-30279 | Alta (7.5) | 0.97% | — | 12 may 2022 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker… |
| CVE-2022-23989 | Alta (7.5) | 0.93% | — | 15 mar 2022 | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback… |
| CVE-2021-3398 | Media (5.8) | 0.92% | — | 10 feb 2022 | Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component. |
| CVE-2021-37613 | Media (6.5) | 0.41% | — | 10 feb 2022 | Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service. |
| CVE-2021-31814 | Media (6.1) | 0.20% | — | 10 feb 2022 | In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client. |
| CVE-2021-31617 | Crítica (9.8) | 2.1% | — | 31 ene 2022 | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code… |
| CVE-2021-28962 | Alta (7.2) | 1.2% | — | 31 ene 2022 | Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands. |