CVE-2023-34198Network Security vulnerability

3 documents3 sources
Severity
7.3HIGHNVD
EPSS
0.3%
top 47.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 29

Description

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-93vc-xxjx-g2p3: In Stormshield Network Security (SNS) 12024-02-29
CVEList
CVE-2023-34198: In Stormshield Network Security (SNS) 12023-12-25
CVE-2023-34198 — Network Security vulnerability | cvebase