CVE-2026-8482

MEDIUM

Stormshield Network Security - Information Leak in NSRPC Client History

Title source: rule
STIX 2.1

Description

A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH multiuser mode is enabled) could possibly get the proxy CA passphrase or TPM password.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (3)
Stormshield/Stormshield Network Security 4.3.0 - 4.3.41
Stormshield/Stormshield Network Security 4.8.0 - 4.8.15
Stormshield/Stormshield Network Security 5.0.0 - 5.0.5
Published Jul 02, 2026
Tracked Since Jul 02, 2026