CVE-2022-46782: High severity stormshield ssl vpn vulnerability
Published Aug 5, 2023
·Updated
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.
Affected Software
1 affected component
Stormshield SSL VPN Client<3.2.0
Event History
Aug 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-46782.
2
What is the severity level of CVE-2022-46782?
CVE-2022-46782 has a severity level of high.
3
What is the affected software for CVE-2022-46782?
The affected software for CVE-2022-46782 is Stormshield SSL VPN Client before version 3.2.0.
4
How can an attacker exploit CVE-2022-46782?
An attacker can exploit CVE-2022-46782 by using the OpenVPN instance to execute malicious code as an administrator on the local machine.
5
Is there a fix available for CVE-2022-46782?
Yes, a fix is available for CVE-2022-46782. Update the Stormshield SSL VPN Client to version 3.2.0 or later.