{"api_version":"1","generated_at":"2026-07-23T20:18:55+00:00","cve":"CVE-2021-28096","urls":{"html":"https://cve.report/CVE-2021-28096","api":"https://cve.report/api/cve/CVE-2021-28096.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-28096","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-28096"},"summary":{"title":"CVE-2021-28096","description":"An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-01-27 14:15:00","updated_at":"2022-02-04 20:57:00"},"problem_types":["CWE-770"],"metrics":[],"references":[{"url":"https://advisories.stormshield.eu/2021-005/","name":"https://advisories.stormshield.eu/2021-005/","refsource":"MISC","tags":[],"title":"DoS on SNS Proxy | Stormshield security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-28096","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28096","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"28096","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"stormshield_network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"28096","vulnerable":"1","versionEndIncluding":"2.7.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"stormshield_network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"28096","vulnerable":"1","versionEndIncluding":"3.11.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"stormshield_network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"28096","vulnerable":"1","versionEndIncluding":"3.7.20","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"stormshield_network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-28096","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://advisories.stormshield.eu/2021-005/","refsource":"MISC","name":"https://advisories.stormshield.eu/2021-005/"}]}},"nvd":{"publishedDate":"2022-01-27 14:15:00","lastModifiedDate":"2022-02-04 20:57:00","problem_types":["CWE-770"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.1","versionEndExcluding":"4.2.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7.6","versionEndIncluding":"3.7.20","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8.0","versionEndIncluding":"3.11.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndIncluding":"2.7.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"28096","Ordinal":"203219","Title":"CVE-2021-28096","CVE":"CVE-2021-28096","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"28096","Ordinal":"1","NoteData":"An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"28096","Ordinal":"2","NoteData":"2022-01-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"28096","Ordinal":"3","NoteData":"2022-01-27","Type":"Other","Title":"Modified"}]}}}