CVE-2022-46783: Weak Encryption
Published Aug 28, 2023
·Updated
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.
Affected Software
1 affected component
Stormshield SSL VPN Client<3.2.0
Event History
Aug 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-46783?
CVE-2022-46783 is an issue in Stormshield SSL VPN Client before version 3.2.0 that allows an attacker to access encrypted address books if multiple address books are used.
2
What is the severity of CVE-2022-46783?
The severity of CVE-2022-46783 is medium with a CVSS score of 5.3.
3
How can an attacker exploit CVE-2022-46783?
An attacker can exploit CVE-2022-46783 by taking advantage of the vulnerability in the Stormshield SSL VPN Client to access encrypted address books when multiple address books are used.
4
How can I fix CVE-2022-46783?
To fix CVE-2022-46783, users should update Stormshield SSL VPN Client to version 3.2.0 or later.