CVE-2023-28616
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the Syslog component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28616?
CVE-2023-28616 has a moderate severity level due to the potential exposure of sensitive information.
How do I fix CVE-2023-28616?
To mitigate CVE-2023-28616, update Stormshield Network Security to versions 4.3.17, 4.6.4, or 4.7.1 or higher.
What type of systems are affected by CVE-2023-28616?
CVE-2023-28616 affects Stormshield Network Security versions prior to 4.3.17, between 4.4.x and 4.6.x before 4.6.4, and 4.7.x before 4.7.1.
What is the impact of CVE-2023-28616 on user accounts?
CVE-2023-28616 can lead to the exposure of user passwords containing an equals sign or space character logged in cleartext.
Can CVE-2023-28616 allow for unauthorized access?
Yes, CVE-2023-28616 may lead to unauthorized access if an attacker can exploit the logged cleartext passwords.