CRITICAL🇵🇱 Wersja polska

CVE-2021-31617

CVSS 9.8v3.1pub. 2022-01-31upd. 2024-11-21

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Stormshield Network Security

    APP
    Stormshield
    1.0.0 – 2.7.9 (excl.)2.8.0 – 3.7.21 (excl.)3.8.0 – 3.11.9 (excl.)4.0.1 – 4.2.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-20032CRITICAL9.8PL ✓same product

ClamAV: RCE przez buffer overflow w parserze partycji HFS+

CVE-2022-37434CRITICAL9.8PL ✓same product

Buffer overflow w zlib podczas przetwarzania nagłówka gzip (inflate)

CVE-2020-7465CRITICAL9.8PL ✓same product

RCE/DoS w implementacji L2TP projektu MPD — błąd zapisu poza buforem

CVE-2025-48707HIGH7.5same product

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information cou...

CVE-2023-34198HIGH7.3same product

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25...