In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HStormshield Network Security
APPStormshield1.0.0 – 2.7.9 (excl.)2.8.0 – 3.7.21 (excl.)3.8.0 – 3.11.9 (excl.)4.0.1 – 4.2.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2023-20032CRITICAL9.8PL ✓same product
ClamAV: RCE przez buffer overflow w parserze partycji HFS+
CVE-2022-37434CRITICAL9.8PL ✓same product
Buffer overflow w zlib podczas przetwarzania nagłówka gzip (inflate)
CVE-2020-7465CRITICAL9.8PL ✓same product
RCE/DoS w implementacji L2TP projektu MPD — błąd zapisu poza buforem
CVE-2025-48707HIGH7.5same product
An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information cou...
CVE-2023-34198HIGH7.3same product
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25...