CVE-2023-34198: Stormshield Network Security

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.

Affected products

  • Stormshield Stormshield Network Security: from 1.0.0, before 3.7.37 (fixed in 3.7.37); from 3.8.0, before 3.11.25 (fixed in 3.11.25); from 4.0.0, before 4.3.19 (fixed in 4.3.19); from 4.4.0, before 4.6.6 (fixed in 4.6.6); version 4.7.0 only

Published 2024-02-29. Last modified 2026-06-17.