CVE-2026-8480

MEDIUM

Connection possible to the Administration portal with a revoked certificate

Title source: cna
STIX 2.1

Description

A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0009
EPSS Percentile 0.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (3)
Stormshield/Stormshield Network Security 4.3.0 - 4.3.41
Stormshield/Stormshield Network Security 4.4.0 - 4.8.15
Stormshield/Stormshield Network Security 5.0.2 EA - 5.0.5
Published Jul 01, 2026
Tracked Since Jul 01, 2026