Vulnerability Details CVE-2023-41165
An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.6%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2023-41165
-
cpe:2.3:a:stormshield:stormshield_network_security:3.10.0
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.0
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.1
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.12
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.13
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.17
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.18
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.19
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.20
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.21
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.22
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.23
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.24
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.25
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.4
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.5
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.8
-
cpe:2.3:a:stormshield:stormshield_network_security:3.11.9
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.0
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.1
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.10
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.13
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.16
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.17
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.20
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.21
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.24
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.25
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.29
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.30
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.33
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.34
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.35
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.36
-
cpe:2.3:a:stormshield:stormshield_network_security:3.7.37
-
cpe:2.3:a:stormshield:stormshield_network_security:4.0.0
-
cpe:2.3:a:stormshield:stormshield_network_security:4.0.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.0.4
-
cpe:2.3:a:stormshield:stormshield_network_security:4.1.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.1.4
-
cpe:2.3:a:stormshield:stormshield_network_security:4.1.5
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.0
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.10
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.11
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.12
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.13
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.14
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.2
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.3
-
cpe:2.3:a:stormshield:stormshield_network_security:4.2.9
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.0
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.10
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.11
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.12
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.12.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.13
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.14
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.15
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.16
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.17
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.18
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.19
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.3
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.4
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.5
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.6
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.7
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.8
-
cpe:2.3:a:stormshield:stormshield_network_security:4.3.9
-
cpe:2.3:a:stormshield:stormshield_network_security:4.4.0
-
cpe:2.3:a:stormshield:stormshield_network_security:4.4.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.5.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.5.2
-
cpe:2.3:a:stormshield:stormshield_network_security:4.5.3
-
cpe:2.3:a:stormshield:stormshield_network_security:4.5.4
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.0
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.1
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.2
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.3
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.4
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.5
-
cpe:2.3:a:stormshield:stormshield_network_security:4.6.6