5.3

CVE-2023-41166

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.

Data is provided by the National Vulnerability Database (NVD)
StormshieldStormshield Network Security Version >= 3.7.0 <= 3.7.39
StormshieldStormshield Network Security Version >= 3.11.0 <= 3.11.27
StormshieldStormshield Network Security Version >= 4.3.0 < 4.3.23
StormshieldStormshield Network Security Version >= 4.6.0 < 4.6.10
StormshieldStormshield Network Security Version >= 4.7.0 < 4.7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.23% 0.458
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N