CVE-2023-28616: Stormshield Network Security

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.

Affected products

  • Stormshield Stormshield Network Security: from 2.7.0, before 4.3.17 (fixed in 4.3.17); from 4.4.0, before 4.6.4 (fixed in 4.6.4); version 4.7.0 only

Published 2023-12-26. Last modified 2026-06-17.