Access Control Flaw in SES Evolution by Stormshield
CVE-2021-31225

7.3HIGH

Key Information:

Vendor
CVE Published:
13 July 2021

What is CVE-2021-31225?

SES Evolution prior to version 2.1.0 contains a vulnerability that enables an attacker with access to an administration console to delete certain resources that are not actively assigned to any security policy. This flaw can potentially lead to unauthorized resource manipulation, which may compromise the integrity and functionality of the security management system.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.