Vulnerabilities > Stormshield > Network Security

DATE CVE VULNERABILITY TITLE RISK
2022-01-17 CVE-2022-22703 Information Exposure Through Log Files vulnerability in Stormshield Network Security 2.0.0/3.0.0
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
local
low complexity
stormshield CWE-532
5.5
2021-12-29 CVE-2021-45885 Insufficient Session Expiration vulnerability in Stormshield Network Security 4.2.2/4.2.3
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).
network
low complexity
stormshield CWE-613
7.5
2021-05-06 CVE-2021-28665 Memory Leak vulnerability in Stormshield Network Security and Stormshield Network Security
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
network
low complexity
stormshield CWE-401
7.5