PT-2023-15028 · Stormshield · Stormshield Ssl Vpn Client

Published

2023-08-28

·

Updated

2023-09-01

·

CVE-2022-46783

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stormshield SSL VPN Client versions prior to 3.2.0
Description An issue was discovered in the Stormshield SSL VPN Client. If multiple address books are used, an attacker may be able to access the other encrypted address book.
Recommendations For versions prior to 3.2.0, update to version 3.2.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of multiple address books to minimize the risk of exploitation.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2022-46783

Affected Products

Stormshield Ssl Vpn Client