CVE-2021-31225: High severity stormshield endpoint security vulnerability
Published Jul 13, 2021
·Updated
SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging access to a computer having the administration console installed.
Affected Software
1 affected component
Stormshield Endpoint Security>=2.0.0<=2.0.2
Event History
Jul 13, 2021
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Frequently Asked Questions
1
What is CVE-2021-31225?
CVE-2021-31225 is a vulnerability in SES Evolution before 2.1.0 that allows deleting some resources not currently in use by any security policy.
2
How severe is CVE-2021-31225?
CVE-2021-31225 has a severity score of 7.3 (high).
3
Which software versions are affected by CVE-2021-31225?
SES Evolution versions between 2.0.0 and 2.0.2 are affected by CVE-2021-31225.
4
How can CVE-2021-31225 be exploited?
CVE-2021-31225 can be exploited by an attacker who has access to a computer with the administration console installed.
5
Where can I find more information about CVE-2021-31225?
You can find more information about CVE-2021-31225 on the Stormshield advisories website: https://advisories.stormshield.eu/2021-027/