Possible DoS on webadmin interface

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2025-004 CVE-2025-24952 , CVE-2025-24953 , CVE-2025-24954 01/10/2025 medium v2

Vulnerability details

It is possible to make the SNS web portal unreachable by opening requests under some conditions.

Impacted products

ProductsSeverityDetail
Stormshield Network Security medium SNS is impacted.

Revisions

Version Date Description
v1 07/17/2025 Initial release
v2 07/13/2026 Published as disclosed


Stormshield Network Security

CVSS v3.1 Overall Score: 4.5      

Analysis

Impacted version

It’s possible for a user who have access to the web admin interface of the SNS appliance to monopolize all available sessions, thus preventing other users from logging in.

Access to the web interface could be blocked, even for legitimate administrators.

SSH access will stay available.

  • SNS 5.0.0 through 5.0.6
  • SNS 4.8.0 through 4.8.15
  • SNS 4.7.0 through 4.7.10
  • SNS 4.0.0 through 4.3.41

Workaround solution

Solution

It is possible to mitigate this attack by reducing the maximum percentage of connections for an IP address.

In file ConfigFiles/auth, change value of the following token:
PercentMaxConnByIp=2

Please note that this setting could be set to different values according to your SNS model. We recommand to set it as low as possible.

The following updates will fix this vulnerability.

  • SNS 5.1.0
  • SNS 5.0.7
  • SNS 4.8.16
  • SNS 4.3.42


Attack Vector Attack Complexity Privileges Required User Interaction Scope Confidentiality Impact Integrity Impact Availability impact
Network Low None None Unchanged None None Low
CVSS Base score: 5.3 CVSS Vector: (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploit Code Maturity Remediation Level Report Confidence
High Workaround Confirmed
CVSS Temporal score: 5.2 CVSS Vector: (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H/RL:W/RC:C)
Confidentiality Requirement (CR) Integrity Requirement (IR) Availability Requirement (AR)
Low Low Low
CVSS Environmental score: 4.5 CVSS Vector: (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H/RL:W/RC:C/CR:L/IR:L/AR:L/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:X/MI:X/MA:X)