Security Flaw in Stormshield Network Security Firewalls
CVE-2023-41165

4.8MEDIUM

Key Information:

Vendor
CVE Published:
29 February 2024

What is CVE-2023-41165?

A security issue exists in Stormshield Network Security firewalls across multiple versions where an administrator with write access can introduce malicious JavaScript into a login disclaimer. This vulnerability can lead to unauthorized data access and potential theft of sensitive information. Proper configuration and restrictions are necessary to mitigate risks associated with this flaw.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.