CVE Vulnerabilities

CVE-2023-41166

Published: Dec 21, 2023 | Modified: Dec 29, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. Its possible to know if a specific user account exists on the SNS firewall by using remote access commands.

Affected Software

Name Vendor Start Version End Version
Stormshield_network_security Stormshield 3.7.0 (including) 3.7.39 (including)
Stormshield_network_security Stormshield 3.11.0 (including) 3.11.27 (including)
Stormshield_network_security Stormshield 4.3.0 (including) 4.3.23 (excluding)
Stormshield_network_security Stormshield 4.6.0 (including) 4.6.10 (excluding)
Stormshield_network_security Stormshield 4.7.0 (including) 4.7.2 (excluding)

References