CVE-2022-46783
Stormshield SSL VPN Client vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2022-46783) was discovered in Stormshield SSL VPN Client versions prior to 3.2.0. The vulnerability was discovered on July 5, 2022, and allows unauthorized access to encrypted address books when multiple address books are in use (Stormshield Advisory).

Technical details

The vulnerability has a CVSS v3.1 base score of 5.3 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The vulnerability is related to inadequate encryption strength (CWE-326) that could allow decryption of address books under specific conditions. The attack vector is local, requiring high attack complexity with low privileges and no user interaction (NVD, Stormshield Advisory).

Impact

If exploited, the vulnerability allows an attacker to access and decrypt other encrypted address books when multiple address books are in use. The impact is primarily focused on confidentiality, with a high confidentiality impact rating but no impact on integrity or availability (Stormshield Advisory).

Exploitability

The exploit code maturity is rated as 'Unproven that exploit exists' with confirmed report confidence. The attack requires local access and high complexity to execute (Stormshield Advisory).

Mitigation and workarounds

There is no workaround solution available for this vulnerability. The only mitigation is to upgrade to Stormshield SSL VPN Client version 3.2.0 or later, which contains the official fix for this vulnerability (Stormshield Advisory).

Additional resources


SourceThis report was generated using AI

Related Stormshield SSL VPN Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-27932HIGH7.8
  • Stormshield SSL VPN Client logoStormshield SSL VPN Client
  • cpe:2.3:a:stormshield:ssl_vpn_client
NoYesAug 25, 2023
CVE-2022-46782HIGH7.8
  • Stormshield SSL VPN Client logoStormshield SSL VPN Client
  • cpe:2.3:a:stormshield:ssl_vpn_client
NoYesAug 05, 2023
CVE-2022-46783MEDIUM5.3
  • Stormshield SSL VPN Client logoStormshield SSL VPN Client
  • cpe:2.3:a:stormshield:ssl_vpn_client
NoYesAug 28, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management