Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34198


In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.


Published

2024-02-29T01:39:48.740

Last Modified

2025-02-14T15:51:57.213

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application stormshield stormshield_network_security < 3.7.37 Yes
Application stormshield stormshield_network_security < 3.11.25 Yes
Application stormshield stormshield_network_security < 4.3.19 Yes
Application stormshield stormshield_network_security < 4.6.6 Yes
Application stormshield stormshield_network_security 4.7.0 Yes

References