An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious HTML content in order to execute JavaScript inside a victim's browser. This results in a stored XSS on the authentication interface of the admin panel. Moreover, an unsecured authentication form is present on the authentication interface of the SSL VPN captive portal. Users are allowed to save their credentials inside the browser. If an administrator saves his credentials through this unsecured form, these credentials could be stolen via the stored XSS on the admin panel without user interaction. Another possible exploitation would be modification of the authentication form of the admin panel into a malicious form.
Conclusion & alert: CVE-2020-11711 is rated Low Risk (30.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.40%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.49% | 0.40% | -0.09% |
| 2 | 2026-05-20 | 0.36% | 0.49% | +0.13% |
| 3 | 2025-11-21 | — | 0.36% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| stormshield | stormshield_network_security | >= 3.6.0, < 3.7.13 | cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* |
| stormshield | stormshield_network_security | >= 3.8.0, < 3.11.0 | cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* |
| stormshield | stormshield_network_security | >= 4.0.0, < 4.1.1 | cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://advisories.stormshield.eu/2020-011/ | Vendor Advisory |
| https://twitter.com/_ACKNAK_ | Not Applicable |
| https://www.digitemis.com/category/blog/actualite/ | Not Applicable |