First published: Tue Dec 26 2023(Updated: )
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stormshield Stormshield Network Security | >=2.7.0<4.3.17 | |
Stormshield Stormshield Network Security | >=4.4.0<4.6.4 | |
Stormshield Stormshield Network Security | =4.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.