NA

CVE-2023-41165

Published: 29/02/2024 Updated: 29/02/2024

Vulnerability Summary

An issue exists in Stormshield Network Security (SNS) 3.7.0 up to and including 3.7.38 prior to 3.7.39, 3.10.0 up to and including 3.11.26 prior to 3.11.27, 4.0 up to and including 4.3.21 prior to 4.3.22, and 4.4.0 up to and including 4.6.8 prior to 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.