VulnerabilityModified
CVE-2022-46783
If multiple address books are used, an attacker may be able to access the other encrypted address book.
MEDIUM 5.3EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- stormshield/ssl vpn client
- Source
- cve@mitre.org
References
- https://advisories.stormshield.eu/Vendor Advisory
- https://advisories.stormshield.eu/2022-029/Vendor Advisory
- https://advisories.stormshield.eu/Vendor Advisory
- https://advisories.stormshield.eu/2022-029/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.