An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49564 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.stormshield.eu/2022-028/ |
|
History
Thu, 17 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-17T14:50:33.961Z
Reserved: 2022-12-07T00:00:00.000Z
Link: CVE-2022-46782
Updated: 2024-08-03T14:39:38.951Z
Status : Modified
Published: 2023-08-05T02:15:10.630
Modified: 2024-11-21T07:31:02.410
Link: CVE-2022-46782
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD