- Description
- An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D293505-FDC0-4B2B-B7D4-8371A9142A0F",
"versionEndExcluding": "4.3.23",
"versionStartIncluding": "4.3.13"
},
{
"criteria": "cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BA3CFA3-AA12-4347-AE99-91D28021E6F0",
"versionEndExcluding": "4.6.10",
"versionStartIncluding": "4.6.0"
},
{
"criteria": "cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "459D63A0-291E-4B60-94A7-4FDB3A381C61",
"versionEndExcluding": "4.7.2",
"versionStartIncluding": "4.7.0"
}
],
"operator": "OR"
}
]
}
]