CVE-2024-37386
- EPSS 0.03%
- Published 15.07.2024 19:15:03
- Last modified 21.11.2024 09:23:45
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3...
CVE-2023-41165
- EPSS 0.58%
- Published 29.02.2024 01:40:58
- Last modified 14.02.2025 15:52:28
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the...
CVE-2023-34198
- EPSS 0.29%
- Published 29.02.2024 01:39:48
- Last modified 14.02.2025 15:51:57
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from a...
CVE-2023-28616
- EPSS 0.1%
- Published 26.12.2023 04:15:07
- Last modified 21.11.2024 07:55:40
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs suc...
CVE-2023-47091
- EPSS 0.18%
- Published 25.12.2023 07:15:09
- Last modified 23.04.2025 17:16:39
An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec con...
CVE-2023-47093
- EPSS 0.07%
- Published 21.12.2023 00:15:26
- Last modified 21.11.2024 08:29:45
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine.
CVE-2023-41166
- EPSS 0.23%
- Published 21.12.2023 00:15:25
- Last modified 21.11.2024 08:20:42
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewal...
CVE-2023-26095
- EPSS 0.19%
- Published 28.08.2023 12:15:08
- Last modified 21.11.2024 07:50:45
ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.
CVE-2020-11711
- EPSS 0.36%
- Published 25.08.2023 16:15:07
- Last modified 21.11.2024 04:58:27
An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authenticat...
CVE-2023-20052
- EPSS 8.86%
- Published 01.03.2023 08:15:11
- Last modified 21.11.2024 07:40:26
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, ...