cve/2023/CVE-2023-34198.md

18 lines
869 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-34198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34198)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
### POC
#### Reference
- https://advisories.stormshield.eu/2023-019
#### Github
No PoCs found on GitHub currently.