An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.
CVE ID: CVE-2023-41166
CVSS Base Severity: LOW
CVSS Base Score: 0.0
Vendor: n/a
Product: n/a
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 29.94% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)