Impact
A flaw in Stormshield Network Security's command history handling can expose secret credentials when administrative CLI commands are executed from the SSH CLI. The vulnerability might reveal the proxy Certificate Authority passphrase or the TPM password, which matches the confidentiality issue defined by CWE-532. The impact is a loss of confidentiality for credentials that could be used to bypass authentication or gain elevated control of the device.
Affected Systems
Stormshield Network Security appliances running versions 4.3.0 through 4.3.41, 4.8.0 through 4.8.15, and 5.0.0 through 5.0.5 are affected; the issue is fixed in SNS 4.3.42, SNS 4.8.16 and SNS 5.0.6.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in a low to medium severity range, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Access requires SSH multi-user mode with administrative privileges to execute CLI commands that trigger the information leak, which is inferred from the description; if SSH is not enabled or the device is in single-user mode the risk is mitigated.
OpenCVE Enrichment