CVE-2021-28962: High severity stormshield network security (sns) vulnerability
Published Jan 31, 2022
·Updated
Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.
Affected Software
8 affected components
Stormshield Network Security>=2.5.0<2.7.9
Stormshield Network Security>=2.8.0<3.7.21
Stormshield Network Security>=3.8.0<3.11.9
Stormshield Network Security>=4.0.0<4.2.2
Stormshield Stormshield Network Security>=2.5.0<2.7.9
Stormshield Stormshield Network Security>=2.8.0<3.7.21
Stormshield Stormshield Network Security>=3.8.0<3.11.9
Stormshield Stormshield Network Security>=4.0.0<4.2.2
Event History
Jan 31, 2022
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28962?
CVE-2021-28962 is a vulnerability in Stormshield Network Security (SNS) before 4.2.2 that allows a read-only administrator to gain privileges via CLI commands.
2
How severe is CVE-2021-28962?
CVE-2021-28962 has a severity level of 7.2, which is considered high.
3
Which software versions are affected by CVE-2021-28962?
The affected software versions include Stormshield Network Security 2.5.0 to 2.7.9, 2.8.0 to 3.7.21, 3.8.0 to 3.11.9, and 4.0.0 to 4.2.2.
4
How can a read-only administrator gain privileges through CVE-2021-28962?
A read-only administrator can gain privileges through CVE-2021-28962 by exploiting CLI commands.
5
Where can I find more information about CVE-2021-28962?
You can find more information about CVE-2021-28962 in the advisories provided by Stormshield at their official website.