In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
References
History

Fri, 14 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Stormshield
Stormshield stormshield Network Security
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*
cpe:2.3:a:stormshield:stormshield_network_security:4.7.0:*:*:*:*:*:*:*
Vendors & Products Stormshield
Stormshield stormshield Network Security
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T16:01:54.191Z

Reserved: 2023-05-30T00:00:00

Link: CVE-2023-34198

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:14.198Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T01:39:48.740

Modified: 2025-02-14T15:51:57.213

Link: CVE-2023-34198

cve-icon Redhat

No data.