CVE-2023-35799
- EPSS 0.03%
- Veröffentlicht 27.06.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:08:43
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.
CVE-2023-35800
- EPSS 0.1%
- Veröffentlicht 27.06.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:08:44
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access ...
CVE-2023-23562
- EPSS 0.13%
- Veröffentlicht 31.05.2023 01:15:43
- Zuletzt bearbeitet 10.01.2025 17:15:10
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.
CVE-2023-23561
- EPSS 0.05%
- Veröffentlicht 30.05.2023 20:15:10
- Zuletzt bearbeitet 14.01.2025 17:15:09
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.
CVE-2022-4304
- EPSS 0.23%
- Veröffentlicht 08.02.2023 20:15:23
- Zuletzt bearbeitet 20.03.2025 21:15:14
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able t...
CVE-2021-45089
- EPSS 0.08%
- Veröffentlicht 21.12.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:55
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
- EPSS 3.82%
- Veröffentlicht 21.12.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:55
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
CVE-2021-45091
- EPSS 0.23%
- Veröffentlicht 21.12.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:56
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
CVE-2021-31220
- EPSS 0.07%
- Veröffentlicht 13.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:19
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
CVE-2021-31221
- EPSS 0.07%
- Veröffentlicht 13.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:19
SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.