CVE-2022-30279
Last modified
CVE-2022-30279 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stormshield | Stormshield Network Security | >= 4.3.3, < 4.3.8 |
References
- https://advisories.stormshield.eu/2022-015Vendor Advisory
- https://advisories.stormshield.eu/2022-015Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-30279?
How severe is CVE-2022-30279?
How do I fix CVE-2022-30279?
Are you affected by CVE-2022-30279?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
