Back

MEDIUM

Information leak in NSRPC client history

Published Jul 2, 2026

Description

A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included)

There is a possible leak of secret information if administration commands have been passed with the CLI command line tool.

Someone with SSH access to the firewall (if SSH multiuser mode is enabled) could possibly get the proxy CA passphrase or TPM password.

Affected products

Remediation

Vendor solution

The following updates fix this vulnerability: * SNS 5.0.6

* SNS 4.8.16

* SNS 4.3.42

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner airbus
Published Jul 2, 2026
Updated Jul 2, 2026
Reserved May 13, 2026
CISA Vulnrichment
Updated Jul 2, 2026
NVD
Status Deferred
Modified Jul 2, 2026
Red Hat
Severity n/a
Public date n/a