Vulnerabilities > Stormshield > Low

DATE CVE VULNERABILITY TITLE RISK
2022-02-10 CVE-2021-37613 Unspecified vulnerability in Stormshield Network Security
Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.
2.9
2022-01-17 CVE-2022-22703 Information Exposure Through Log Files vulnerability in Stormshield Network Security 2.0.0/3.0.0
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
local
low complexity
stormshield CWE-532
2.1
2021-12-21 CVE-2021-45089 Unspecified vulnerability in Stormshield Endpoint Security 2.0.0/2.0.2/2.1.0
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
2.3
2021-07-13 CVE-2021-31224 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.
2.9
2021-07-13 CVE-2021-31223 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.
2.9
2021-07-13 CVE-2021-31222 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed.
2.9
2021-07-13 CVE-2021-31221 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed.
2.9
2021-07-13 CVE-2021-31220 Unspecified vulnerability in Stormshield Endpoint Security
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
2.3