Vulnerabilities > Stormshield > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-14 CVE-2022-32213 HTTP Request Smuggling vulnerability in multiple products
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
6.5
2022-07-14 CVE-2022-32214 HTTP Request Smuggling vulnerability in multiple products
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests.
network
low complexity
llhttp nodejs debian stormshield CWE-444
6.5
2022-07-14 CVE-2022-32215 HTTP Request Smuggling vulnerability in multiple products
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers.
6.5
2022-05-12 CVE-2022-30279 NULL Pointer Dereference vulnerability in Stormshield Network Security 4.3.4/4.3.5
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.
network
low complexity
stormshield CWE-476
5.0
2022-03-15 CVE-2022-23989 Unspecified vulnerability in Stormshield Network Security
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface.
network
low complexity
stormshield
5.0
2022-02-10 CVE-2021-31814 Missing Authentication for Critical Function vulnerability in Stormshield Network Security
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.
local
low complexity
stormshield CWE-306
6.1
2022-02-10 CVE-2021-3398 Integer Overflow or Wraparound vulnerability in Stormshield Network Security
Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.
network
low complexity
stormshield CWE-190
5.0
2022-01-31 CVE-2021-28962 Unspecified vulnerability in Stormshield Network Security
Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.
network
low complexity
stormshield
6.5
2022-01-27 CVE-2021-28096 Allocation of Resources Without Limits or Throttling vulnerability in Stormshield Network Security
An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used).
4.3
2021-12-29 CVE-2021-45885 Insufficient Session Expiration vulnerability in Stormshield Network Security
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).
4.3