CVE-2023-47091
An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47091?
CVE-2023-47091 is considered to have a high severity due to its potential to disrupt IPsec connections.
How do I fix CVE-2023-47091?
To resolve CVE-2023-47091, upgrade your Stormshield Network Security software to version 4.3.23, 4.6.10, or 4.7.2 or later.
Which versions of Stormshield Network Security are affected by CVE-2023-47091?
CVE-2023-47091 affects versions 4.3.13 to 4.3.22, 4.6.0 to 4.6.9, and 4.7.0 to 4.7.1 of Stormshield Network Security.
What type of attack does CVE-2023-47091 enable?
CVE-2023-47091 enables attackers to overflow the cookie threshold, resulting in failure of IPsec connections.
Is there a workaround for CVE-2023-47091 if I cannot upgrade?
Currently, there are no documented workarounds for CVE-2023-47091, therefore upgrading is the recommended solution.