CVE-2023-26095: Input Validation
Published Aug 28, 2023
·Updated
ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.
Affected Software
4 affected components
Stormshield Network Security>=4.6.0<4.6.3
Stormshield Network Security=4.3.15
Stormshield Stormshield Network Security>=4.6.0<4.6.3
Stormshield Stormshield Network Security=4.3.15
Event History
Aug 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-26095?
CVE-2023-26095 is a vulnerability in Stormshield Network Security (SNS) that allows a crash when analyzing a crafted SIP packet.
2
What is the severity of CVE-2023-26095?
The severity of CVE-2023-26095 is high (CVSS score: 7.5).
3
Which versions of Stormshield Network Security are affected by CVE-2023-26095?
Stormshield Network Security versions 4.3.15, 4.6.0 to 4.6.3 are affected by CVE-2023-26095.
4
How can I fix CVE-2023-26095?
To fix CVE-2023-26095, update Stormshield Network Security to version 4.3.16 or 4.6.3.
5
Where can I find more information about CVE-2023-26095?
More information about CVE-2023-26095 can be found at the following link: [https://advisories.stormshield.eu/2023-007/](https://advisories.stormshield.eu/2023-007/).