
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2022-46783) was discovered in Stormshield SSL VPN Client versions prior to 3.2.0. The vulnerability was discovered on July 5, 2022, and allows unauthorized access to encrypted address books when multiple address books are in use (Stormshield Advisory).
The vulnerability has a CVSS v3.1 base score of 5.3 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The vulnerability is related to inadequate encryption strength (CWE-326) that could allow decryption of address books under specific conditions. The attack vector is local, requiring high attack complexity with low privileges and no user interaction (NVD, Stormshield Advisory).
If exploited, the vulnerability allows an attacker to access and decrypt other encrypted address books when multiple address books are in use. The impact is primarily focused on confidentiality, with a high confidentiality impact rating but no impact on integrity or availability (Stormshield Advisory).
The exploit code maturity is rated as 'Unproven that exploit exists' with confirmed report confidence. The attack requires local access and high complexity to execute (Stormshield Advisory).
There is no workaround solution available for this vulnerability. The only mitigation is to upgrade to Stormshield SSL VPN Client version 3.2.0 or later, which contains the official fix for this vulnerability (Stormshield Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."