CVE-2023-34198
Last modified
CVE-2023-34198 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stormshield | Stormshield Network Security | >= 1.0.0, < 3.7.37 |
| Stormshield | Stormshield Network Security | >= 3.8.0, < 3.11.25 |
| Stormshield | Stormshield Network Security | >= 4.0.0, < 4.3.19 |
| Stormshield | Stormshield Network Security | >= 4.4.0, < 4.6.6 |
| Stormshield | Stormshield Network Security | 4.7.0 |
References
- https://advisories.stormshield.eu/2023-019Vendor Advisory
- https://advisories.stormshield.eu/2023-019Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-34198?
How severe is CVE-2023-34198?
How do I fix CVE-2023-34198?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-34192Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 al…9
- CVE-2023-34193File Upload vulnerability in Zimbra ZCS 8.8.15 allows an aut…8.8
- CVE-2023-34194StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp …7.5
- CVE-2023-34195An issue was discovered in SystemFirmwareManagementRuntimeDx…7.8
- CVE-2023-34196In the Keyfactor EJBCA before 8.0.0, the RA web certificate …8.2
- CVE-2023-34197Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk…5.4
- CVE-2023-3420Type Confusion in V8 in Google Chrome prior to 114.0.5735.19…8.8
- CVE-2023-34203In Progress OpenEdge OEM (OpenEdge Management) and OEE (Open…8.8
- CVE-2023-34204imapsync through 2.229 uses predictable paths under /tmp and…6.5
- CVE-2023-34205In Moov signedxml through 1.0.0, parsing the raw XML (as rec…9.1
- CVE-2023-34207Unrestricted upload of file with dangerous type vulnerabilit…8.8
- CVE-2023-34208Path Traversal in create template function in EasyUse MailHu…6.5
Are you affected by CVE-2023-34198?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
