Vulnerability Description
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stormshield | Stormshield Network Security | >= 1.0.0, < 3.7.37 |
References
- https://advisories.stormshield.eu/2023-019Vendor Advisory
- https://advisories.stormshield.eu/2023-019Vendor Advisory
FAQ
What is CVE-2023-34198?
CVE-2023-34198 is a vulnerability with a CVSS score of 7.3 (HIGH). In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4...
How severe is CVE-2023-34198?
CVE-2023-34198 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34198?
Check the references section above for vendor advisories and patch information. Affected products include: Stormshield Stormshield Network Security.