A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH multiuser mode is enabled) could possibly get the proxy CA passphrase or TPM password.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.3.0, <= 4.3.41CPE match | cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* | ||
>= 4.8.0, <= 4.8.15CPE match | cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.0.5CPE match | cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.