CVE-2021-28096: Medium severity stormshield network security vulnerability
Published Jan 27, 2022
·Updated
An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.
Affected Software
4 affected components
Stormshield Stormshield Network Security>=2.0.0<=2.7.8
Stormshield Stormshield Network Security>=3.7.6<=3.7.20
Stormshield Stormshield Network Security>=3.8.0<=3.11.8
Stormshield Stormshield Network Security>=4.0.1<4.2.3
Event History
Jan 27, 2022
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28096?
CVE-2021-28096 is a vulnerability discovered in Stormshield SNS before version 4.2.3 (when the proxy is used).
2
How does CVE-2021-28096 impact Stormshield SNS?
CVE-2021-28096 allows an attacker to saturate the proxy connection table, resulting in the proxy denying any new connections.
3
What is the severity of CVE-2021-28096?
CVE-2021-28096 has a severity rating of 5.3 (Medium).
4
Which versions of Stormshield SNS are affected by CVE-2021-28096?
Stormshield SNS versions 2.0.0 to 2.7.8, 3.7.6 to 3.7.20, 3.8.0 to 3.11.8, and 4.0.1 to 4.2.3 are affected by CVE-2021-28096.
5
How can I fix CVE-2021-28096 in my Stormshield SNS installation?
To fix CVE-2021-28096, update your Stormshield SNS installation to version 4.2.3 or later.