Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23989


In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface. This could result in the blocking of almost all network traffic, making the firewall unreachable. An attacker could exploit this via forged and properly timed traffic to cause a denial of service.


Published

2022-03-15T21:15:09.603

Last Modified

2024-11-21T06:49:36.520

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application stormshield stormshield_network_security < 3.7.25 Yes
Application stormshield stormshield_network_security < 3.11.13 Yes
Application stormshield stormshield_network_security < 4.2.10 Yes
Application stormshield stormshield_network_security < 4.3.5 Yes

References