In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LStormshield Network Security
APPStormshield4.7.01.0.0 – 3.7.37 (excl.)3.8.0 – 3.11.25 (excl.)4.0.0 – 4.3.19 (excl.)4.4.0 – 4.6.6 (excl.)
Related vulnerabilities
ClamAV: RCE przez buffer overflow w parserze partycji HFS+
Buffer overflow w zlib podczas przetwarzania nagłówka gzip (inflate)
RCE w Stormshield Network Security — błąd zarządzania pamięcią w ASQ
RCE/DoS w implementacji L2TP projektu MPD — błąd zapisu poza buforem
An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information cou...