CVE-2022-22703: Medium severity stormshield network security (sns) vulnerability
Published Jan 17, 2022
·Updated
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
Affected Software
3 affected components
Stormshield Network Security>=2.0.0<2.1.1
Stormshield Network Security>=3.0.0<3.0.2
Microsoft Windows
Event History
Jan 17, 2022
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue in Stormshield SSO Agent?
The vulnerability ID for this security issue in Stormshield SSO Agent is CVE-2022-22703.
2
What is the severity rating of CVE-2022-22703?
CVE-2022-22703 has a severity rating of 5.5, which is considered medium.
3
Which versions of Stormshield SSO Agent are affected by this vulnerability?
Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2 are affected by this vulnerability.
4
What is the impact of this vulnerability?
This vulnerability allows the cleartext user password and PSK to be contained in the log file of the .exe installer.
5
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following link: [https://advisories.stormshield.eu/2022-001](https://advisories.stormshield.eu/2022-001)