CVE-2021-28665: High severity stormshield network security (sns) vulnerability
Published May 6, 2021
·Updated
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
Affected Software
5 affected components
Stormshield Network Security>=3.0.0<3.7.18
Stormshield Network Security>=3.8.0<3.11.5
Stormshield Network Security>=4.0.0<4.1.5
Stormshield Stormshield Network Security>=3.8.0<3.11.5
Stormshield Stormshield Network Security>=4.0.0<4.1.5
Event History
May 6, 2021
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28665?
CVE-2021-28665 is a vulnerability in Stormshield SNS that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
2
What is the severity of CVE-2021-28665?
CVE-2021-28665 has a severity rating of 7.5 (High).
3
Which versions of Stormshield SNS are affected by CVE-2021-28665?
Stormshield SNS versions before 3.7.18, 3.11.6, and 4.1.6 are affected by CVE-2021-28665.
4
How can CVE-2021-28665 be exploited?
CVE-2021-28665 can be exploited by sending specially crafted SNMP requests to the affected Stormshield SNS device.
5
Is there a fix available for CVE-2021-28665?
Yes, upgrading to Stormshield SNS version 3.7.18, 3.11.6, or 4.1.6 will fix the vulnerability.