An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NStormshield Network Security
APPStormshield< 5.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2023-20032CRITICAL9.8PL ✓same product
ClamAV: RCE przez buffer overflow w parserze partycji HFS+
CVE-2022-37434CRITICAL9.8PL ✓same product
Buffer overflow w zlib podczas przetwarzania nagłówka gzip (inflate)
CVE-2021-31617CRITICAL9.8PL ✓same product
RCE w Stormshield Network Security — błąd zarządzania pamięcią w ASQ
CVE-2020-7465CRITICAL9.8PL ✓same product
RCE/DoS w implementacji L2TP projektu MPD — błąd zapisu poza buforem
CVE-2023-34198HIGH7.3same product
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25...