CVE-2023-34198: Stormshield Network Security
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
Affected products
- Stormshield Stormshield Network Security: from 1.0.0, before 3.7.37 (fixed in 3.7.37); from 3.8.0, before 3.11.25 (fixed in 3.11.25); from 4.0.0, before 4.3.19 (fixed in 4.3.19); from 4.4.0, before 4.6.6 (fixed in 4.6.6); version 4.7.0 only
Published 2024-02-29. Last modified 2026-06-17.