Product:

Endpoint_security

(Stormshield)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 15
Date Id Summary Products Score Patch Annotated
2021-07-13 CVE-2021-31221 SES Evolution before 2.1.0 allows deleting some parts of a security policy by leveraging access to a computer having the administration console installed. Endpoint_security 5.7
2021-07-13 CVE-2021-31222 SES Evolution before 2.1.0 allows updating some parts of a security policy by leveraging access to a computer having the administration console installed. Endpoint_security 5.7
2021-07-13 CVE-2021-31223 SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed. Endpoint_security 5.7
2021-07-13 CVE-2021-31224 SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies. Endpoint_security 3.5
2021-07-13 CVE-2021-35957 Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones. Endpoint_security 6.7
2021-12-21 CVE-2021-45089 Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control. Endpoint_security 5.2
2021-12-21 CVE-2021-45090 Stormshield Endpoint Security before 2.1.2 allows remote code execution. Endpoint_security 9.8
2021-12-21 CVE-2021-45091 Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control. Endpoint_security 4.3
2023-06-27 CVE-2023-35799 Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges. Endpoint_security 5.5
2023-06-27 CVE-2023-35800 Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators. Endpoint_security 4.3