CVE-2023-34198
HIGHDescription
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
Is your site exposed to CVE-2023-34198?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| stormshield | stormshield_network_security |
| stormshield | stormshield_network_security |
| stormshield | stormshield_network_security |
| stormshield | stormshield_network_security |
| stormshield | stormshield_network_security |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-34198? +
How severe is CVE-2023-34198? +
What products are affected by CVE-2023-34198? +
How do I check if I'm vulnerable to CVE-2023-34198? +
Related Vulnerabilities
An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, …
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 …