Vulnerabilities > Stormshield > Stormshield Network Security > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-26 CVE-2023-28616 Cleartext Transmission of Sensitive Information vulnerability in Stormshield Network Security
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1.
network
low complexity
stormshield CWE-319
7.5
2023-12-25 CVE-2023-47091 Classic Buffer Overflow vulnerability in Stormshield Network Security
An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2.
network
low complexity
stormshield CWE-120
7.5
2023-08-28 CVE-2023-26095 Unspecified vulnerability in Stormshield Network Security
ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.
network
low complexity
stormshield
7.5
2023-02-08 CVE-2022-4450 Double Free vulnerability in multiple products
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g.
network
low complexity
openssl stormshield CWE-415
7.5
2023-02-08 CVE-2023-0286 Type Confusion vulnerability in multiple products
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName.
network
high complexity
openssl stormshield CWE-843
7.4
2022-10-31 CVE-2022-40617 Resource Exhaustion vulnerability in multiple products
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
7.5
2022-08-24 CVE-2022-27812 Unspecified vulnerability in Stormshield Network Security
Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS.
network
low complexity
stormshield
7.5
2022-05-12 CVE-2022-30279 NULL Pointer Dereference vulnerability in Stormshield Network Security
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.
network
low complexity
stormshield CWE-476
7.5
2022-03-15 CVE-2022-23989 Unspecified vulnerability in Stormshield Network Security
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface.
network
low complexity
stormshield
7.5
2022-01-31 CVE-2021-28962 Unspecified vulnerability in Stormshield Network Security
Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.
network
low complexity
stormshield
7.2