XSS with certificate manipulation

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2020-012 04/15/2020 medium v1

Vulnerability details

A XSS stored in a certificate can be triggered if the certificate is manipulated via the GUI.

Impacted products

ProductsSeverityDetail
Stormshield Network Security medium impacted

Revisions

Version Date Description
v1 Initial release


Stormshield Network Security

CVSS v2 Overall Score: 4.1      

Analysis

Impacted version

If a stored certificate contains malicious code, this can be triggered using the GUI. This can lead to XSS manipulation.

  • SNS 4.0.0 to 4.0.4

Workaround solution

Solution

There is no workaround solution.

The 4.1.1 update fix this vulnerability.



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Adjacent Network Medium Single Complete Complete Complete
CVSS Base score: 7.4 CVSS Vector: (AV:A/AC:M/Au:S/C:C/I:C/A:C)
Exploitability Remediation Level Report Confidence
Unproven that exploit exists Official fix Confirmed
CVSS Temporal score: 5.4 CVSS Vector: (AV:A/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
None Medium [26-75%]
CVSS Environmental score: 4.1 CVSS Vector: (AV:A/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C/CDP:N/TD:M/CR:ND/IR:ND/AR:ND)