CVE-2021-3384: Medium severity Stormshield Network Security vulnerability
A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Stormshield Network Securityto a version that resolves this vulnerability.Fixed in 2.7.8 - Upgrade
Upgrade
Stormshield Network Securityto a version that resolves this vulnerability.Fixed in 3.7.17 - Upgrade
Upgrade
Stormshield Network Securityto a version that resolves this vulnerability.Fixed in 3.11.5 - Upgrade
Upgrade
Stormshield Network Securityto a version that resolves this vulnerability.Fixed in 4.2.0
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3384.
What is the severity of CVE-2021-3384?
The severity of CVE-2021-3384 is medium with a CVSS score of 5.3.
Which versions of Stormshield Network Security are affected by CVE-2021-3384?
Versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.5, and 4.0.0 to 4.1.5 of Stormshield Network Security are affected.
How does CVE-2021-3384 impact the system?
CVE-2021-3384 could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system from contacting new hosts via IPv4 or IPv6.
Is there a fix available for CVE-2021-3384?
Yes, a fix is available for CVE-2021-3384. It is recommended to update to a patched version of Stormshield Network Security.