Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41165


An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.


Published

2024-02-29T01:40:58.383

Last Modified

2025-02-14T15:52:28.190

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application stormshield stormshield_network_security < 3.7.39 Yes
Application stormshield stormshield_network_security < 3.11.27 Yes
Application stormshield stormshield_network_security < 4.3.22 Yes
Application stormshield stormshield_network_security < 4.6.9 Yes

References