First published: Tue Dec 26 2023(Updated: )
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stormshield Network Security | >=2.7.0<4.3.17 | |
Stormshield Network Security | >=4.4.0<4.6.4 | |
Stormshield Network Security | =4.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28616 has a moderate severity level due to the potential exposure of sensitive information.
To mitigate CVE-2023-28616, update Stormshield Network Security to versions 4.3.17, 4.6.4, or 4.7.1 or higher.
CVE-2023-28616 affects Stormshield Network Security versions prior to 4.3.17, between 4.4.x and 4.6.x before 4.6.4, and 4.7.x before 4.7.1.
CVE-2023-28616 can lead to the exposure of user passwords containing an equals sign or space character logged in cleartext.
Yes, CVE-2023-28616 may lead to unauthorized access if an attacker can exploit the logged cleartext passwords.