Impact
A revoked client certificate can still authenticate to Stormshield Network Security’s captive‑admin portal, permitting an attacker who owns the revoked certificate to obtain full administrative control. The flaw, classified as CWE‑295, represents a failure to enforce certificate revocation checks during authentication.
Affected Systems
Stormshield Network Security firmware versions 4.3.0 through 4.3.41, 4.4.0 through 4.8.15, and 5.0.2 EA through 5.0.5 are affected. The issue resides in the captive‑admin portal component of these products.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the medium severity range% indicates a very low likelihood of exploitation at present, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to possess a revoked client certificate and to reach the captive‑admin portal, likely via network access to the device. The attack vector is inferred to be remote access to the portal’s administrative interface, with the attacker bypassing proper revocation validation.
OpenCVE Enrichment