Stormshield records
60 published records for vendor stormshield.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference3
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-787 Out-of-bounds Write2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-284 Improper Access Control2
The weakness classes this vendor ships most often: where to look.
CWEAll records
60 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2022-32214No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Medium6.5 | — | 82.5% | Jul 14, 2022 |
48Plan | CVE-2023-20032No exploit | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file pclamav · clamav · CWE-120 | Critical9.8 | — | 29.3% | Mar 1, 2023 |
47Plan | CVE-2022-32215No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Medium6.5 | — | 68.8% | Jul 14, 2022 |
47Plan | CVE-2023-0286No exploit | X.400 address type confusion in X.509 GeneralNameopenssl · openssl · CWE-843 | High7.4 | — | 59.5% | Feb 8, 2023 |
45Plan | CVE-2022-37434Proof of concept | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.zlib · zlib · CWE-787 | Critical9.8 | — | 19.0% | Aug 5, 2022 |
40Plan | CVE-2020-7465No exploit | The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Causmpd project · mpd · CWE-787 | Critical9.8 | — | 3.0% | Oct 6, 2020 |
40Plan | CVE-2021-45090No exploit | Stormshield Endpoint Security before 2.1.2 allows remote code execution.stormshield · endpoint security | Critical9.8 | — | 2.9% | Dec 21, 2021 |
40Plan | CVE-2021-31617No exploit | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.stormshield · stormshield network security · CWE-119 | Critical9.8 | — | 2.1% | Jan 31, 2022 |
39Monitor | CVE-2022-32213No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding hellhttp · llhttp · CWE-444 | Medium6.5 | — | 44.1% | Jul 14, 2022 |
37Monitor | CVE-2002-20001Proof of concept | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pubbalasys · dheater · CWE-400 | High7.5 | — | 24.6% | Nov 11, 2021 |
36Monitor | CVE-2022-4450No exploit | Double free after calling PEM_read_bio_exopenssl · openssl · CWE-415 | High7.5 | — | 20.4% | Feb 8, 2023 |
32Monitor | CVE-2018-20850No exploit | Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.stormshield · stormshield network security · CWE-79 | High8.2 | — | 0.4% | Jul 4, 2019 |
31Monitor | CVE-2023-0215No exploit | Use-after-free following BIO_new_NDEFopenssl · openssl · CWE-416 | High7.5 | — | 4.5% | Feb 8, 2023 |
31Monitor | CVE-2020-7466No exploit | The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the mpd project · mpd · CWE-125 | High7.5 | — | 2.0% | Oct 6, 2020 |
31Monitor | CVE-2023-0216No exploit | Invalid pointer dereference in d2i_PKCS7 functionsopenssl · openssl · CWE-476 | High7.5 | — | 1.8% | Feb 8, 2023 |
31Monitor | CVE-2023-0401No exploit | NULL dereference during PKCS7 data verificationopenssl · openssl · CWE-476 | High7.5 | — | 1.8% | Feb 8, 2023 |
31Monitor | CVE-2022-40617No exploit | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and istrongswan · strongswan · CWE-400 | High7.5 | — | 1.7% | Oct 31, 2022 |
31Monitor | CVE-2021-27932No exploit | Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.stormshield · ssl vpn client | High7.8 | — | 0.2% | Aug 25, 2023 |
31Monitor | CVE-2022-46782No exploit | An issue was discovered in Stormshield SSL VPN Client before 3.2.0.stormshield · ssl vpn client | High7.8 | — | 0.2% | Aug 4, 2023 |
30Monitor | CVE-2021-28665No exploit | Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive cstormshield · network security · CWE-401 | High7.5 | — | 1.0% | May 6, 2021 |
30Monitor | CVE-2022-30279No exploit | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.stormshield · stormshield network security · CWE-476 | High7.5 | — | 1.0% | May 12, 2022 |
30Monitor | CVE-2021-28127No exploit | An issue was discovered in Stormshield SNS through 4.2.1.stormshield · stormshield network security · CWE-307 | High7.5 | — | 0.9% | Jul 1, 2021 |
30Monitor | CVE-2022-23989No exploit | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a floodstormshield · stormshield network security | High7.5 | — | 0.9% | Mar 15, 2022 |
30Monitor | CVE-2021-45885No exploit | An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).stormshield · network security · CWE-613 | High7.5 | — | 0.9% | Dec 29, 2021 |
30Monitor | CVE-2022-27812No exploit | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can leastormshield · stormshield network security | High7.5 | — | 0.8% | Aug 24, 2022 |
- CVE-2022-3221451Plan
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
MediumCVSS 6.5No exploitEPSS 82%llhttp · llhttpJul 14, 2022
- CVE-2023-2003248Plan
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file p
CriticalCVSS 9.8No exploitEPSS 29%clamav · clamavMar 1, 2023
- CVE-2022-3221547Plan
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
MediumCVSS 6.5No exploitEPSS 69%llhttp · llhttpJul 14, 2022
- CVE-2023-028647Plan
X.400 address type confusion in X.509 GeneralName
HighCVSS 7.4No exploitEPSS 60%openssl · opensslFeb 8, 2023
- CVE-2022-3743445Plan
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
CriticalCVSS 9.8Proof of conceptEPSS 19%zlib · zlibAug 5, 2022
- CVE-2020-746540Plan
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Caus
CriticalCVSS 9.8No exploitEPSS 3%mpd project · mpdOct 6, 2020
- CVE-2021-4509040Plan
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
CriticalCVSS 9.8No exploitEPSS 3%stormshield · endpoint securityDec 21, 2021
- CVE-2021-3161740Plan
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.
CriticalCVSS 9.8No exploitEPSS 2%stormshield · stormshield network securityJan 31, 2022
- CVE-2022-3221339Monitor
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he
MediumCVSS 6.5No exploitEPSS 44%llhttp · llhttpJul 14, 2022
- CVE-2002-2000137Monitor
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pub
HighCVSS 7.5Proof of conceptEPSS 25%balasys · dheaterNov 11, 2021
- CVE-2022-445036Monitor
Double free after calling PEM_read_bio_ex
HighCVSS 7.5No exploitEPSS 20%openssl · opensslFeb 8, 2023
- CVE-2018-2085032Monitor
Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.
HighCVSS 8.2No exploitEPSS 0%stormshield · stormshield network securityJul 4, 2019
- CVE-2023-021531Monitor
Use-after-free following BIO_new_NDEF
HighCVSS 7.5No exploitEPSS 4%openssl · opensslFeb 8, 2023
- CVE-2020-746631Monitor
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the
HighCVSS 7.5No exploitEPSS 2%mpd project · mpdOct 6, 2020
- CVE-2023-021631Monitor
Invalid pointer dereference in d2i_PKCS7 functions
HighCVSS 7.5No exploitEPSS 2%openssl · opensslFeb 8, 2023
- CVE-2023-040131Monitor
NULL dereference during PKCS7 data verification
HighCVSS 7.5No exploitEPSS 2%openssl · opensslFeb 8, 2023
- CVE-2022-4061731Monitor
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and i
HighCVSS 7.5No exploitEPSS 2%strongswan · strongswanOct 31, 2022
- CVE-2021-2793231Monitor
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
HighCVSS 7.8No exploitEPSS 0%stormshield · ssl vpn clientAug 25, 2023
- CVE-2022-4678231Monitor
An issue was discovered in Stormshield SSL VPN Client before 3.2.0.
HighCVSS 7.8No exploitEPSS 0%stormshield · ssl vpn clientAug 4, 2023
- CVE-2021-2866530Monitor
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive c
HighCVSS 7.5No exploitEPSS 1%stormshield · network securityMay 6, 2021
- CVE-2022-3027930Monitor
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.
HighCVSS 7.5No exploitEPSS 1%stormshield · stormshield network securityMay 12, 2022
- CVE-2021-2812730Monitor
An issue was discovered in Stormshield SNS through 4.2.1.
HighCVSS 7.5No exploitEPSS 1%stormshield · stormshield network securityJul 1, 2021
- CVE-2022-2398930Monitor
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood
HighCVSS 7.5No exploitEPSS 1%stormshield · stormshield network securityMar 15, 2022
- CVE-2021-4588530Monitor
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).
HighCVSS 7.5No exploitEPSS 1%stormshield · network securityDec 29, 2021
- CVE-2022-2781230Monitor
Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lea
HighCVSS 7.5No exploitEPSS 1%stormshield · stormshield network securityAug 24, 2022