CVE-2021-31220: Medium severity stormshield endpoint security vulnerability
Published Jul 13, 2021
·Updated
SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.
Affected Software
1 affected component
Stormshield Endpoint Security>=2.0.0<=2.0.2
Event History
Jul 13, 2021
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
Description
Frequently Asked Questions
1
What is CVE-2021-31220?
CVE-2021-31220 is a vulnerability in SES Evolution before version 2.1.0 that allows modifying security policies by leveraging access of a user with read-only access to security policies.
2
How severe is CVE-2021-31220?
CVE-2021-31220 has a severity rating of 5.2, which is considered medium.
3
What software is affected by CVE-2021-31220?
Stormshield Endpoint Security versions 2.0.0 to 2.0.2 are affected by CVE-2021-31220.
4
How can the security policies be modified in SES Evolution?
The security policies in SES Evolution can be modified by leveraging the access of a user with read-only access to security policies.
5
How can I fix CVE-2021-31220?
To fix CVE-2021-31220, it is recommended to upgrade to version 2.1.0 of SES Evolution.