CVE-2025-48707

7.5

Stormshield · Network Security (SNS)

Stormshield Network Security (SNS) versions prior to 5.0.1 contain a flaw where TPM authentication data may be shared between administrators in specific high availability configurations.

Executive summary

A critical authentication-related flaw in Stormshield Network Security (SNS) allows for the potential exposure of sensitive secrets between administrators in high availability environments.

Vulnerability

The vulnerability involves the improper handling of TPM authentication information within high availability (HA) clusters, which can lead to the unauthorized sharing of secrets among administrative users.

Business impact

This vulnerability presents a significant risk to the integrity of administrative access controls within secured network environments. By exposing sensitive authentication secrets, an attacker could potentially gain unauthorized access or escalate privileges, undermining the security posture of the affected network security appliances. Given the CVSS score of 7.5, this is classified as a high severity issue that requires prompt remediation to prevent potential compromise of administrative sessions.

Remediation

Immediate Action: Upgrade all Stormshield Network Security (SNS) instances to version 5.0.1 or later to resolve the secret sharing issue.

Proactive Monitoring: Review administrative access logs and monitor HA cluster synchronization events for any anomalies that may indicate unauthorized secret propagation.

Compensating Controls: Restrict administrative access to the management interfaces of the affected appliances to trusted personnel only until the patch is applied.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

The risk posed by the potential exposure of TPM secrets in high availability deployments necessitates immediate attention. Administrators must prioritize updating to version 5.0.1 to ensure that administrative credentials and secrets remain isolated and secure. Failing to patch this vulnerability may allow for lateral movement or unauthorized access within the management plane of the network infrastructure.

Sources