Stormshield develops a focused portfolio of network security and endpoint protection products, including firewalls, VPN clients, and centralized management systems that defend enterprise perimeters and remote access infrastructure. The vendor's vulnerability footprint is moderate in volume and more prominent than typical in the landscape, with a meaningful share of disclosures reaching serious severity and concentrated across input-handling and protocol-interpretation weaknesses such as buffer overflows, cross-site scripting, and HTTP request smuggling. These recurring classes reflect the parsing demands of edge-facing security appliances and web-connected management interfaces, where input validation flaws can undermine the security guarantees the products are meant to provide. Defenders should prioritize updates to internet-reachable instances such as VPN endpoints and management consoles; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stormshield over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32214MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Sm | Jul 14, 2022 | 6.5 | 67 | NO | NO |
CVE-2023-0286HIGH There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but
the public structure def | Feb 8, 2023 | 7.4 | 60 | NO | NO |
CVE-2022-32215MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smug | Jul 14, 2022 | 6.5 | 52 | NO | NO |
CVE-2023-20032CRITICAL On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earli | Mar 1, 2023 | 9.8 | 48 | NO | NO |
CVE-2022-32213MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smugg | Jul 14, 2022 | 6.5 | 44 | NO | NO |
CVE-2022-37434CRITICAL zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHe | Aug 5, 2022 | 9.8 | 41 | NO | NO |
CVE-2002-20001HIGH The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-s | Nov 11, 2021 | 7.5 | 38 | NO | NO |
CVE-2022-4450HIGH The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and
decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data.
If the function succeeds th | Feb 8, 2023 | 7.5 | 35 | NO | NO |
CVE-2021-45090CRITICAL Stormshield Endpoint Security before 2.1.2 allows remote code execution. | Dec 21, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-31617CRITICAL In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory m | Jan 31, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stormshield.
Media articles that mention a CVE ID that affects a product developed by Stormshield — matched by CVE ID, not by vendor name.