Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Stormshield Network Security HIGH 7.5
CVE-2025-48707

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared amo…

Fix: 5.0.1+
Fix from $1,950 2025-09-25
Stormshield Network Security HIGH 7.3
CVE-2023-34198

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4…

Fix: 3.7.37 / 3.11.25+
Fix from $1,950 2024-02-29
Stormshield Network Security HIGH 7.5
CVE-2023-28616

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects use…

Fix: 4.3.17 / 4.6.4+
Fix from $1,950 2023-12-26
Stormshield Network Security HIGH 7.5
CVE-2023-47091

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS…

Fix: 4.3.23 / 4.6.10+
Fix from $1,950 2023-12-25
Stormshield Network Security MEDIUM 6.5
CVE-2023-47093

An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may…

Fix: 4.3.22 / 4.6.9+
Fix from $1,600 2023-12-21
Stormshield Network Security MEDIUM 5.3
CVE-2023-41166

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9…

Fix: 4.3.23 / 4.6.10+
Fix from $1,600 2023-12-21
Stormshield Network Security HIGH 7.5
CVE-2023-26095

ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.

Fix: 4.6.3+
Fix from $1,950 2023-08-28
Ssl Vpn Client MEDIUM 5.3
CVE-2022-46783

An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other e…

Fix: 3.2.0+
Fix from $1,600 2023-08-28
Ssl Vpn Client HIGH 7.8
CVE-2021-27932

Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

Fix: after 3.0.0
Fix from $1,950 2023-08-25
Ssl Vpn Client HIGH 7.8
CVE-2022-46782

An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN inst…

Fix: 3.2.0+
Fix from $1,950 2023-08-05
Endpoint Security MEDIUM 5.5
CVE-2023-35799

Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create a…

Fix: after 2.3.2
Fix from $1,600 2023-06-27
Endpoint Security MEDIUM 5.5
CVE-2023-23561

Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.

Fix: 2.4.1+
Fix from $1,600 2023-05-30
Stormshield Network Security HIGH 7.5
CVE-2022-27812

Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS …

Fix: 3.7.30 / 3.11.18+
Fix from $1,950 2022-08-24
Stormshield Network Security HIGH 7.5
CVE-2022-30279

An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dere…

Fix: 4.3.8+
Fix from $1,950 2022-05-12
Stormshield Network Security HIGH 7.5
CVE-2022-23989

In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of conne…

Fix: 3.7.25 / 3.11.13+
Fix from $1,950 2022-03-15
Stormshield Network Security MEDIUM 6.5
CVE-2021-37613

Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.

Fix: after 4.2.7
Fix from $1,600 2022-02-10
Stormshield Network Security MEDIUM 6.1
CVE-2021-31814

In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the…

Fix: after 2.9.0
Fix from $1,600 2022-02-10
Stormshield Network Security MEDIUM 5.8
CVE-2021-3398

Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.

Fix: after 3.11.12
Fix from $1,600 2022-02-10
Stormshield Network Security CRITICAL 9.8
CVE-2021-31617

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through…

Fix: 2.7.9 / 3.7.21+
Fix from $2,300 2022-01-31
Stormshield Network Security HIGH 7.2
CVE-2021-28962

Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.

Fix: 2.7.9 / 3.7.21+
Fix from $1,950 2022-01-31
Stormshield Network Security MEDIUM 5.3
CVE-2021-28096

An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would res…

Fix: 4.2.3+
Fix from $1,600 2022-01-27
Network Security MEDIUM 5.5
CVE-2022-22703

In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe install…

Fix: 2.1.1 / 3.0.2+
Fix from $1,600 2022-01-17
Network Security HIGH 7.5
CVE-2021-45885

An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the f…

Fix: 4.2.8+
Fix from $1,950 2021-12-29
Endpoint Security CRITICAL 9.8
CVE-2021-45090

Stormshield Endpoint Security before 2.1.2 allows remote code execution.

Fix: 2.1.2+
Fix from $2,300 2021-12-21
Endpoint Security MEDIUM 5.2
CVE-2021-45089

Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.

Fix: 2.1.2+
Fix from $1,600 2021-12-21
Endpoint Security MEDIUM 6.7
CVE-2021-35957

Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the…

Fix: after 2.0.2
Fix from $1,600 2021-07-13
Endpoint Security MEDIUM 5.7
CVE-2021-31221

SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console insta…

Fix: after 2.0.2
Fix from $1,600 2021-07-13
Endpoint Security MEDIUM 5.7
CVE-2021-31222

SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console insta…

Fix: after 2.0.2
Fix from $1,600 2021-07-13
Endpoint Security MEDIUM 5.7
CVE-2021-31223

SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console instal…

Fix: after 2.0.2
Fix from $1,600 2021-07-13
Endpoint Security MEDIUM 5.2
CVE-2021-31220

SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.

Fix: after 2.0.2
Fix from $1,600 2021-07-13