Description
A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included)



A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.
Published: 2026-07-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A revoked client certificate can still authenticate to Stormshield Network Security’s captive‑admin portal, allowing an attacker who possesses such a certificate to gain full administrative control. The flaw is a failure to enforce certificate revocation checks during authentication, identified as CWE‑295. Because the portal accepts a revoked certificate, the attacker can bypass normal authentication controls and reach privileged operations that could alter device configuration or compromise other network assets.

Affected Systems

Stormshield Network Security firmware versions 4.3.0 through 4.3.41, 4.4.0 through 4.8.15, and 5.0.2 EA through 5.0.5 are affected. The vulnerability resides in the captive‑admin portal component that handles client‑certificate authentication.

Risk and Exploitability

The CVSS score of 4.3 places the vulnerability in the medium severity range. The EPSS score of less than 1% indicates a very low likelihood of exploitation currently, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to possess a revoked client certificate and to reach the captive‑admin portal, most likely via network access to the device. The attack vector is inferred to be remote access to the portal’s administrative interface, with the attacker bypassing proper revocation validation.

Generated by OpenCVE AI on August 1, 2026 at 23:19 UTC.

Remediation

Vendor Solution

The following updates fix this vulnerability: * SNS 5.0.6 * SNS 4.8.16 * SNS 4.3.42


OpenCVE Recommended Actions

  • Upgrade the device to a firmware version that includes the revocation fix (SNS 5.0.6, SNS 4.8.16, or SNS 4.3.42).
  • If an upgrade cannot be performed immediately, enforce an additional authentication factor such as a password or one‑time password for captive‑admin portal access to mitigate the risk of unauthorized entry.
  • Restrict network access to the captive‑admin portal by configuring firewall rules to allow connections only from trusted IP ranges.

Generated by OpenCVE AI on August 1, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Stormshield
Stormshield stormshield Network Security
Vendors & Products Stormshield
Stormshield stormshield Network Security

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.
Title Connection possible to the Administration portal with a revoked certificate
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Stormshield Stormshield Network Security
cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-07-01T15:45:32.124Z

Reserved: 2026-05-13T13:48:21.232Z

Link: CVE-2026-8480

cve-icon Vulnrichment

Updated: 2026-07-01T15:45:27.327Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-01T16:16:53.730

Modified: 2026-07-01T19:59:44.537

Link: CVE-2026-8480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:30:04Z

Weaknesses
  • CWE-295

    Improper Certificate Validation