Stormshield

Stormshield Network Security

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 10.02.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:15:31

Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.

  • EPSS 0.04%
  • Veröffentlicht 10.02.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:06:17

In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.

  • EPSS 3.01%
  • Veröffentlicht 31.01.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:06:02

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.

  • EPSS 0.76%
  • Veröffentlicht 31.01.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:27

Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.

  • EPSS 0.38%
  • Veröffentlicht 27.01.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 05:59:05

An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.

Exploit
  • EPSS 14.68%
  • Veröffentlicht 11.11.2021 19:15:07
  • Zuletzt bearbeitet 22.08.2025 10:33:16

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ate...

  • EPSS 0.22%
  • Veröffentlicht 01.07.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:59:08

An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

  • EPSS 0.47%
  • Veröffentlicht 06.05.2021 20:15:09
  • Zuletzt bearbeitet 21.11.2024 06:00:03

Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

  • EPSS 0.19%
  • Veröffentlicht 19.03.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:58:07

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This iss...

  • EPSS 0.38%
  • Veröffentlicht 02.03.2021 18:15:15
  • Zuletzt bearbeitet 21.11.2024 06:21:23

A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7...