Vulnerabilities > Stormshield > Endpoint Security

DATE CVE VULNERABILITY TITLE RISK
2023-06-27 CVE-2023-35799 Incorrect Permission Assignment for Critical Resource vulnerability in Stormshield Endpoint Security
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions.
local
low complexity
stormshield CWE-732
5.5
2023-06-27 CVE-2023-35800 Incorrect Permission Assignment for Critical Resource vulnerability in Stormshield Endpoint Security
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions.
network
low complexity
stormshield CWE-732
4.3
2023-05-31 CVE-2023-23562 Unspecified vulnerability in Stormshield Endpoint Security
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.
network
low complexity
stormshield
4.3
2023-05-30 CVE-2023-23561 Unspecified vulnerability in Stormshield Endpoint Security
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.
local
low complexity
stormshield
5.5
2023-02-08 CVE-2022-4304 Information Exposure Through Discrepancy vulnerability in multiple products
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack.
network
high complexity
openssl stormshield CWE-203
5.9
2021-12-21 CVE-2021-45089 Unspecified vulnerability in Stormshield Endpoint Security 2.0.0/2.0.2/2.1.0
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
2.3
2021-12-21 CVE-2021-45090 Unspecified vulnerability in Stormshield Endpoint Security 2.0.0/2.0.2/2.1.0
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
network
low complexity
stormshield
critical
10.0
2021-12-21 CVE-2021-45091 Unspecified vulnerability in Stormshield Endpoint Security 2.1.0/2.1.1
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
network
low complexity
stormshield
4.0
2021-07-13 CVE-2021-31220 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
2.3
2021-07-13 CVE-2021-31221 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.
2.9