Vulnerabilities > CVE-2021-45885 - Insufficient Session Expiration vulnerability in Stormshield Network Security 4.2.2/4.2.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
stormshield
CWE-613

Summary

An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

Vulnerable Configurations

Part Description Count
Application
Stormshield
2

Common Weakness Enumeration (CWE)