Записи Stormshield
60 опубликованных записей вендора stormshield.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 25 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference3
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-787 Out-of-bounds Write2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-284 Improper Access Control2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
60 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2022-32214Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Средняя6,5 | — | 82,5 % | 14 июл. 2022 г. |
48В плане | CVE-2023-20032Эксплойта нет | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file pclamav · clamav · CWE-120 | Критическая9,8 | — | 29,3 % | 1 мар. 2023 г. |
47В плане | CVE-2022-32215Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Средняя6,5 | — | 68,8 % | 14 июл. 2022 г. |
47В плане | CVE-2023-0286Эксплойта нет | X.400 address type confusion in X.509 GeneralNameopenssl · openssl · CWE-843 | Высокая7,4 | — | 59,5 % | 8 февр. 2023 г. |
45В плане | CVE-2022-37434Proof of concept | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.zlib · zlib · CWE-787 | Критическая9,8 | — | 19,0 % | 5 авг. 2022 г. |
40В плане | CVE-2020-7465Эксплойта нет | The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Causmpd project · mpd · CWE-787 | Критическая9,8 | — | 3,0 % | 6 окт. 2020 г. |
40В плане | CVE-2021-45090Эксплойта нет | Stormshield Endpoint Security before 2.1.2 allows remote code execution.stormshield · endpoint security | Критическая9,8 | — | 2,9 % | 21 дек. 2021 г. |
40В плане | CVE-2021-31617Эксплойта нет | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.stormshield · stormshield network security · CWE-119 | Критическая9,8 | — | 2,1 % | 31 янв. 2022 г. |
39Наблюдать | CVE-2022-32213Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding hellhttp · llhttp · CWE-444 | Средняя6,5 | — | 44,1 % | 14 июл. 2022 г. |
37Наблюдать | CVE-2002-20001Proof of concept | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pubbalasys · dheater · CWE-400 | Высокая7,5 | — | 24,6 % | 11 нояб. 2021 г. |
36Наблюдать | CVE-2022-4450Эксплойта нет | Double free after calling PEM_read_bio_exopenssl · openssl · CWE-415 | Высокая7,5 | — | 20,4 % | 8 февр. 2023 г. |
32Наблюдать | CVE-2018-20850Эксплойта нет | Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.stormshield · stormshield network security · CWE-79 | Высокая8,2 | — | 0,4 % | 4 июл. 2019 г. |
31Наблюдать | CVE-2023-0215Эксплойта нет | Use-after-free following BIO_new_NDEFopenssl · openssl · CWE-416 | Высокая7,5 | — | 4,5 % | 8 февр. 2023 г. |
31Наблюдать | CVE-2020-7466Эксплойта нет | The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the mpd project · mpd · CWE-125 | Высокая7,5 | — | 2,0 % | 6 окт. 2020 г. |
31Наблюдать | CVE-2023-0216Эксплойта нет | Invalid pointer dereference in d2i_PKCS7 functionsopenssl · openssl · CWE-476 | Высокая7,5 | — | 1,8 % | 8 февр. 2023 г. |
31Наблюдать | CVE-2023-0401Эксплойта нет | NULL dereference during PKCS7 data verificationopenssl · openssl · CWE-476 | Высокая7,5 | — | 1,8 % | 8 февр. 2023 г. |
31Наблюдать | CVE-2022-40617Эксплойта нет | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and istrongswan · strongswan · CWE-400 | Высокая7,5 | — | 1,7 % | 31 окт. 2022 г. |
31Наблюдать | CVE-2021-27932Эксплойта нет | Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.stormshield · ssl vpn client | Высокая7,8 | — | 0,2 % | 25 авг. 2023 г. |
31Наблюдать | CVE-2022-46782Эксплойта нет | An issue was discovered in Stormshield SSL VPN Client before 3.2.0.stormshield · ssl vpn client | Высокая7,8 | — | 0,2 % | 4 авг. 2023 г. |
30Наблюдать | CVE-2021-28665Эксплойта нет | Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive cstormshield · network security · CWE-401 | Высокая7,5 | — | 1,0 % | 6 мая 2021 г. |
30Наблюдать | CVE-2022-30279Эксплойта нет | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.stormshield · stormshield network security · CWE-476 | Высокая7,5 | — | 1,0 % | 12 мая 2022 г. |
30Наблюдать | CVE-2021-28127Эксплойта нет | An issue was discovered in Stormshield SNS through 4.2.1.stormshield · stormshield network security · CWE-307 | Высокая7,5 | — | 0,9 % | 1 июл. 2021 г. |
30Наблюдать | CVE-2022-23989Эксплойта нет | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a floodstormshield · stormshield network security | Высокая7,5 | — | 0,9 % | 15 мар. 2022 г. |
30Наблюдать | CVE-2021-45885Эксплойта нет | An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).stormshield · network security · CWE-613 | Высокая7,5 | — | 0,9 % | 29 дек. 2021 г. |
30Наблюдать | CVE-2022-27812Эксплойта нет | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can leastormshield · stormshield network security | Высокая7,5 | — | 0,8 % | 24 авг. 2022 г. |
- CVE-2022-3221451В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
СредняяCVSS 6,5Эксплойта нетEPSS 82 %llhttp · llhttp14 июл. 2022 г.
- CVE-2023-2003248В плане
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file p
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %clamav · clamav1 мар. 2023 г.
- CVE-2022-3221547В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
СредняяCVSS 6,5Эксплойта нетEPSS 69 %llhttp · llhttp14 июл. 2022 г.
- CVE-2023-028647В плане
X.400 address type confusion in X.509 GeneralName
ВысокаяCVSS 7,4Эксплойта нетEPSS 60 %openssl · openssl8 февр. 2023 г.
- CVE-2022-3743445В плане
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
КритическаяCVSS 9,8Proof of conceptEPSS 19 %zlib · zlib5 авг. 2022 г.
- CVE-2020-746540В плане
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Caus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mpd project · mpd6 окт. 2020 г.
- CVE-2021-4509040В плане
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %stormshield · endpoint security21 дек. 2021 г.
- CVE-2021-3161740В плане
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %stormshield · stormshield network security31 янв. 2022 г.
- CVE-2022-3221339Наблюдать
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he
СредняяCVSS 6,5Эксплойта нетEPSS 44 %llhttp · llhttp14 июл. 2022 г.
- CVE-2002-2000137Наблюдать
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pub
ВысокаяCVSS 7,5Proof of conceptEPSS 25 %balasys · dheater11 нояб. 2021 г.
- CVE-2022-445036Наблюдать
Double free after calling PEM_read_bio_ex
ВысокаяCVSS 7,5Эксплойта нетEPSS 20 %openssl · openssl8 февр. 2023 г.
- CVE-2018-2085032Наблюдать
Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %stormshield · stormshield network security4 июл. 2019 г.
- CVE-2023-021531Наблюдать
Use-after-free following BIO_new_NDEF
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openssl · openssl8 февр. 2023 г.
- CVE-2020-746631Наблюдать
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mpd project · mpd6 окт. 2020 г.
- CVE-2023-021631Наблюдать
Invalid pointer dereference in d2i_PKCS7 functions
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openssl · openssl8 февр. 2023 г.
- CVE-2023-040131Наблюдать
NULL dereference during PKCS7 data verification
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openssl · openssl8 февр. 2023 г.
- CVE-2022-4061731Наблюдать
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and i
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %strongswan · strongswan31 окт. 2022 г.
- CVE-2021-2793231Наблюдать
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %stormshield · ssl vpn client25 авг. 2023 г.
- CVE-2022-4678231Наблюдать
An issue was discovered in Stormshield SSL VPN Client before 3.2.0.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %stormshield · ssl vpn client4 авг. 2023 г.
- CVE-2021-2866530Наблюдать
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive c
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stormshield · network security6 мая 2021 г.
- CVE-2022-3027930Наблюдать
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stormshield · stormshield network security12 мая 2022 г.
- CVE-2021-2812730Наблюдать
An issue was discovered in Stormshield SNS through 4.2.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stormshield · stormshield network security1 июл. 2021 г.
- CVE-2022-2398930Наблюдать
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stormshield · stormshield network security15 мар. 2022 г.
- CVE-2021-4588530Наблюдать
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stormshield · network security29 дек. 2021 г.
- CVE-2022-2781230Наблюдать
Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lea
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stormshield · stormshield network security24 авг. 2022 г.