CVE-2023-41166
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41166?
The severity of CVE-2023-41166 is currently classified as medium due to the potential for user enumeration on the SNS firewall.
How do I fix CVE-2023-41166?
To fix CVE-2023-41166, upgrade to a version of Stormshield Network Security that is not affected, specifically any version above 3.7.39, 3.11.27, 4.3.22, 4.6.9, or 4.7.1.
What versions of Stormshield Network Security are affected by CVE-2023-41166?
Versions 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1 are affected by CVE-2023-41166.
What type of vulnerability is CVE-2023-41166?
CVE-2023-41166 is a user enumeration vulnerability that allows unauthorized parties to determine if a specific user account exists.
Can CVE-2023-41166 be exploited remotely?
Yes, CVE-2023-41166 can be exploited remotely using specific access commands on the affected Stormshield Network Security systems.