Show filters
58 Total Results
Displaying 1-10 of 58
Sort by:
Attacker Value
Unknown
CVE-2022-4304
Disclosure Date: February 08, 2023 (last updated February 14, 2025)
A timing based side channel exists in the OpenSSL RSA Decryption implementation
which could be sufficient to recover a plaintext across a network in a
Bleichenbacher style attack. To achieve a successful decryption an attacker
would have to be able to send a very large number of trial messages for
decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5,
RSA-OEAP and RSASVE.
For example, in a TLS connection, RSA is commonly used by a client to send an
encrypted pre-master secret to the server. An attacker that had observed a
genuine connection between a client and a server could use this flaw to send
trial messages to the server and record the time taken to process them. After a
sufficiently large number of messages the attacker could recover the pre-master
secret used for the original connection and thus be able to decrypt the
application data sent over that connection.
1
Attacker Value
Unknown
CVE-2023-41165
Disclosure Date: February 29, 2024 (last updated February 15, 2025)
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.
0
Attacker Value
Unknown
CVE-2023-34198
Disclosure Date: February 29, 2024 (last updated February 15, 2025)
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
0
Attacker Value
Unknown
CVE-2023-28616
Disclosure Date: December 26, 2023 (last updated August 21, 2024)
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.
0
Attacker Value
Unknown
CVE-2023-47091
Disclosure Date: December 25, 2023 (last updated August 21, 2024)
An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.
0
Attacker Value
Unknown
CVE-2023-47093
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine.
0
Attacker Value
Unknown
CVE-2023-41166
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.
0
Attacker Value
Unknown
CVE-2023-26095
Disclosure Date: August 28, 2023 (last updated August 21, 2024)
ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.
0
Attacker Value
Unknown
CVE-2022-46783
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.
0
Attacker Value
Unknown
CVE-2021-27932
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
0