CVE-2023-47091: Stormshield Network Security

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.

Affected products

  • Stormshield Stormshield Network Security: from 4.3.13, before 4.3.23 (fixed in 4.3.23); from 4.6.0, before 4.6.10 (fixed in 4.6.10); from 4.7.0, before 4.7.2 (fixed in 4.7.2)

Published 2023-12-25. Last modified 2026-06-17.