📦 Stormshield Network Security

by Stormshield

🔍 What is Stormshield Network Security?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-20032

CRITICAL CVSS 9.8 Mar 1, 2023

A heap buffer overflow vulnerability in ClamAV's HFS+ partition file parser allows remote unauthenticated attackers to execute arbitrary code or cause denial of service. This affects ClamAV versions 1...

CVE-2021-31617

CRITICAL CVSS 9.8 Jan 31, 2022

This vulnerability in Stormshield Network Security (SNS) ASQ allows remote attackers to execute arbitrary code due to improper memory management. It affects multiple versions across SNS product lines....

CVE-2020-7465

CRITICAL CVSS 9.8 Oct 6, 2020

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service through memory corruption in MPD's L2TP implementation. Attackers can exploit it by sending specially cr...

CVE-2025-48707

HIGH CVSS 7.5 Sep 25, 2025

A vulnerability in Stormshield Network Security (SNS) firewalls allows TPM authentication information to be shared among administrators in certain high-availability configurations. This can lead to un...

CVE-2023-34198

HIGH CVSS 7.3 Feb 29, 2024

This vulnerability in Stormshield Network Security (SNS) firewalls occurs when a Network object created from an inactive DHCP interface is used in filtering rules, causing the firewall to treat it as ...

CVE-2023-28616

HIGH CVSS 7.5 Dec 26, 2023

This vulnerability in Stormshield Network Security (SNS) logs user passwords containing equals signs or spaces in cleartext when processed by the serverd component, potentially exposing them in system...

CVE-2023-47091

HIGH CVSS 7.5 Dec 25, 2023

This vulnerability in Stormshield Network Security (SNS) firewalls allows attackers to overflow the cookie threshold, preventing IPsec connections from being established. It affects SNS versions 4.3.1...

CVE-2023-26095

HIGH CVSS 7.5 Aug 28, 2023

A vulnerability in Stormshield Network Security (SNS) ASQ component allows remote attackers to cause a denial-of-service crash by sending a specially crafted SIP packet. This affects SNS firewall appl...

CVE-2023-0286

HIGH CVSS 7.4 Feb 8, 2023

CVE-2023-0286 is a type confusion vulnerability in OpenSSL's X.400 address processing that can cause memory corruption when CRL checking is enabled. Attackers can potentially read memory contents or c...

CVE-2022-4450

HIGH CVSS 7.5 Feb 8, 2023

A double-free vulnerability in OpenSSL's PEM parsing functions allows attackers to cause denial of service through specially crafted PEM files. The vulnerability affects applications that parse PEM fi...

CVE-2022-23989

HIGH CVSS 7.5 Mar 15, 2022

This vulnerability in Stormshield Network Security (SNS) firewalls allows an attacker to cause a denial of service by flooding the SSLVPN service with connections, saturating the loopback interface an...

CVE-2021-28962

HIGH CVSS 7.2 Jan 31, 2022

This vulnerability allows read-only administrators in Stormshield Network Security (SNS) firewalls to escalate privileges via CLI commands, gaining higher-level administrative access. It affects SNS f...

CVE-2021-28127

HIGH CVSS 7.5 Jul 1, 2021

This vulnerability in Stormshield Network Security (SNS) firewalls allows brute-force attacks against authentication mechanisms. Attackers can attempt to guess credentials repeatedly, potentially gain...