CVE-2022-30279: Null Pointer Dereference
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30279?
CVE-2022-30279 is a vulnerability discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8, which allows an attacker to trigger a NULL pointer dereference and crash the SNS system.
How severe is CVE-2022-30279?
CVE-2022-30279 has a severity level of 7.5 (high).
How does CVE-2022-30279 affect Stormshield Network Security?
CVE-2022-30279 affects Stormshield Network Security versions 4.3.3 to 4.3.8.
What is the impact of CVE-2022-30279?
The impact of CVE-2022-30279 is a crash of the SNS system due to a NULL pointer dereference triggered by forged sofbus lacbus traffic.
Is there a fix available for CVE-2022-30279?
Yes, a fix for CVE-2022-30279 is available in version 4.3.8 of Stormshield Network Security.