CVE-2023-41166
21.12.2023, 00:15
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.Enginsight
| Vendor | Product | Version |
|---|---|---|
| stormshield | stormshield_network_security | 3.7.0 ≤ 𝑥 ≤ 3.7.39 |
| stormshield | stormshield_network_security | 3.11.0 ≤ 𝑥 ≤ 3.11.27 |
| stormshield | stormshield_network_security | 4.3.0 ≤ 𝑥 < 4.3.23 |
| stormshield | stormshield_network_security | 4.6.0 ≤ 𝑥 < 4.6.10 |
| stormshield | stormshield_network_security | 4.7.0 ≤ 𝑥 < 4.7.2 |
𝑥
= Vulnerable software versions