CVE-2023-34198
In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34198?
CVE-2023-34198 has been classified as a significant vulnerability affecting multiple versions of Stormshield Network Security.
How do I fix CVE-2023-34198?
To fix CVE-2023-34198, update Stormshield Network Security to version 3.7.37 or higher, 3.11.25 or higher, 4.3.19 or higher, 4.6.6 or higher, or 4.7.1 or higher.
What versions of Stormshield Network Security are affected by CVE-2023-34198?
CVE-2023-34198 affects Stormshield Network Security versions 1.0.0 through 3.7.36, 3.8.0 through 3.11.24, 4.0.0 through 4.3.18, 4.4.0 through 4.6.5, and 4.7.0.
What type of vulnerability is CVE-2023-34198?
CVE-2023-34198 is a vulnerability related to the use of a Network object created from an inactive DHCP interface.
Is CVE-2023-34198 exploitable remotely?
Yes, CVE-2023-34198 can potentially be exploited remotely if the affected versions of Stormshield Network Security are exposed to untrusted networks.