Impact
A revoked client certificate can still authenticate to Stormshield Network Security’s captive‑admin portal, allowing an attacker who possesses such a certificate to gain full administrative control. The flaw is a failure to enforce certificate revocation checks during authentication, identified as CWE‑295. Because the portal accepts a revoked certificate, the attacker can bypass normal authentication controls and reach privileged operations that could alter device configuration or compromise other network assets.
Affected Systems
Stormshield Network Security firmware versions 4.3.0 through 4.3.41, 4.4.0 through 4.8.15, and 5.0.2 EA through 5.0.5 are affected. The vulnerability resides in the captive‑admin portal component that handles client‑certificate authentication.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the medium severity range. The EPSS score of less than 1% indicates a very low likelihood of exploitation currently, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to possess a revoked client certificate and to reach the captive‑admin portal, most likely via network access to the device. The attack vector is inferred to be remote access to the portal’s administrative interface, with the attacker bypassing proper revocation validation.
OpenCVE Enrichment