CVE-2023-41165

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/02/2024
Last modified:
14/02/2025

Description

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* 3.7.0 (including) 3.7.39 (excluding)
cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* 3.10.0 (including) 3.11.27 (excluding)
cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* 4.0.0 (including) 4.3.22 (excluding)
cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* 4.4.0 (including) 4.6.9 (excluding)