cve/2023/CVE-2023-41166.md

18 lines
749 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-41166](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41166)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.
### POC
#### Reference
- https://advisories.stormshield.eu/2023-027
#### Github
No PoCs found on GitHub currently.