CVE-2023-47091

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 25, 2023
Updated: Aug 20, 2024
CWE ID 120

Summary

CVE-2023-47091 is a vulnerability affecting Stormshield Network Security (SNS) versions 4.3.13 to 4.3.22 before 4.3.23, 4.6.0 to 4.6.9 before 4.6.10, and 4.7.0 to 4.7.1 before 4.7.2. This issue allows an attacker to overflow the cookie threshold, rendering IPsec connections inoperable, potentially disrupting network security and data protection. The vulnerability poses a serious risk, as IPsec is crucial for secure communication between networks and remote access. Users are advised to update their SNS software to a patched version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share