CVE-2023-28616: Stormshield Network Security
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.
Affected products
- Stormshield Stormshield Network Security: from 2.7.0, before 4.3.17 (fixed in 4.3.17); from 4.4.0, before 4.6.4 (fixed in 4.6.4); version 4.7.0 only
Published 2023-12-26. Last modified 2026-06-17.