CVE-2021-31617Improper Restriction of Operations within the Bounds of a Memory Buffer in Network Security

Severity
9.8CRITICALNVD
EPSS
3.0%
top 13.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateFeb 8

Description

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-43x4-rqpq-prmp: In ASQ in Stormshield Network Security (SNS) 12022-02-08
CVEList
CVE-2021-31617: In ASQ in Stormshield Network Security (SNS) 12022-01-31
CVE-2021-31617 — Network Security vulnerability | cvebase