Stormshield Network Security

Vendor:

First CVE: Jul 4, 2019 · Active for 7 years

37
Total CVEs
More Total CVEs than 97% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Stormshield Network Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 4, 2019
7 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

CVE Severity & Scoring

Stormshield Network Security37 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local3 (8.1%)
Network30 (81.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (10.8%)
Attack Complexity
Low35 (94.6%)
High2 (5.4%)
Unknown0 (0.0%)
User Interaction
None32 (86.5%)
Unknown0 (0.0%)
Required5 (13.5%)
Privileges Required
Low1 (2.7%)
High5 (13.5%)
None31 (83.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure def
Feb 8, 20237.460NONO
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earli
Mar 1, 20239.848NONO
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHe
Aug 5, 20229.841NONO
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-s
Nov 11, 20217.538NONO
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds th
Feb 8, 20237.535NONO
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory m
Jan 31, 20229.831NONO
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or caus
Oct 6, 20209.830NONO
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack.
Feb 8, 20235.926NONO
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contain
Oct 31, 20227.526NONO
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secre
Jul 2, 20264.325NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Stormshield Network Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.7.037.10.4%00
4.4.028.72.5%00
4.3.1517.50.6%00
4.2.117.50.9%00
1.1.016.10.2%00