Stormshield

Endpoint Security

15 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 27.06.2023 17:15:10
  • Last modified 21.11.2024 08:08:43

Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.

  • EPSS 0.1%
  • Published 27.06.2023 17:15:10
  • Last modified 21.11.2024 08:08:44

Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access ...

  • EPSS 0.13%
  • Published 31.05.2023 01:15:43
  • Last modified 10.01.2025 17:15:10

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.

  • EPSS 0.05%
  • Published 30.05.2023 20:15:10
  • Last modified 14.01.2025 17:15:09

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.

  • EPSS 0.23%
  • Published 08.02.2023 20:15:23
  • Last modified 20.03.2025 21:15:14

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able t...

  • EPSS 0.08%
  • Published 21.12.2021 16:15:10
  • Last modified 21.11.2024 06:31:55

Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.

  • EPSS 3.82%
  • Published 21.12.2021 16:15:10
  • Last modified 21.11.2024 06:31:55

Stormshield Endpoint Security before 2.1.2 allows remote code execution.

  • EPSS 0.23%
  • Published 21.12.2021 16:15:10
  • Last modified 21.11.2024 06:31:56

Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.

  • EPSS 0.07%
  • Published 13.07.2021 14:15:08
  • Last modified 21.11.2024 06:05:19

SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.

  • EPSS 0.07%
  • Published 13.07.2021 14:15:08
  • Last modified 21.11.2024 06:05:19

SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.