CVE Vulnerabilities

CVE-2023-41166

Published: Dec 21, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. Its possible to know if a specific user account exists on the SNS firewall by using remote access commands.

Affected Software

NameVendorStart VersionEnd Version
Stormshield_network_securityStormshield3.7.0 (including)3.7.39 (including)
Stormshield_network_securityStormshield3.11.0 (including)3.11.27 (including)
Stormshield_network_securityStormshield4.3.0 (including)4.3.23 (excluding)
Stormshield_network_securityStormshield4.6.0 (including)4.6.10 (excluding)
Stormshield_network_securityStormshield4.7.0 (including)4.7.2 (excluding)

References