VulnerabilityModified
CVE-2023-47091
An attacker can overflow the cookie threshold, making an IPsec connection impossible.
HIGH 7.5EPSS 0.53%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- stormshield/stormshield network security
- Source
- cve@mitre.org
References
- https://advisories.stormshield.euVendor Advisory
- https://advisories.stormshield.eu/2023-024/Vendor Advisory
- https://advisories.stormshield.euVendor Advisory
- https://advisories.stormshield.eu/2023-024/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.