CVE-2025-48707

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.
References
Link Resource
https://advisories.stormshield.eu/2025-003/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*

History

14 Oct 2025, 19:43

Type Values Removed Values Added
First Time Stormshield stormshield Network Security
Stormshield
CPE cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*
References () https://advisories.stormshield.eu/2025-003/ - () https://advisories.stormshield.eu/2025-003/ - Vendor Advisory

26 Sep 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-284

25 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-25 18:15

Updated : 2025-10-14 19:43


NVD link : CVE-2025-48707

Mitre link : CVE-2025-48707

CVE.ORG link : CVE-2025-48707


JSON object : View

Products Affected

stormshield

  • stormshield_network_security
CWE
CWE-284

Improper Access Control