CVE-2025-48707

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.
References
Link Resource
https://advisories.stormshield.eu/2025-003/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*

History

14 Oct 2025, 19:43

Type Values Removed Values Added
CPE cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*
References () https://advisories.stormshield.eu/2025-003/ - () https://advisories.stormshield.eu/2025-003/ - Vendor Advisory
First Time Stormshield
Stormshield stormshield Network Security

26 Sep 2025, 20:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

25 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-25 18:15

Updated : 2025-10-14 19:43


NVD link : CVE-2025-48707

Mitre link : CVE-2025-48707

CVE.ORG link : CVE-2025-48707


JSON object : View

Products Affected

stormshield

  • stormshield_network_security
CWE
CWE-284

Improper Access Control