First published: Thu Jan 27 2022(Updated: )
An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stormshield Stormshield Network Security | >=2.0.0<=2.7.8 | |
Stormshield Stormshield Network Security | >=3.7.6<=3.7.20 | |
Stormshield Stormshield Network Security | >=3.8.0<=3.11.8 | |
Stormshield Stormshield Network Security | >=4.0.1<4.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28096 is a vulnerability discovered in Stormshield SNS before version 4.2.3 (when the proxy is used).
CVE-2021-28096 allows an attacker to saturate the proxy connection table, resulting in the proxy denying any new connections.
CVE-2021-28096 has a severity rating of 5.3 (Medium).
Stormshield SNS versions 2.0.0 to 2.7.8, 3.7.6 to 3.7.20, 3.8.0 to 3.11.8, and 4.0.1 to 4.2.3 are affected by CVE-2021-28096.
To fix CVE-2021-28096, update your Stormshield SNS installation to version 4.2.3 or later.