Lucene search

K
cveF-SecureUSCVE-2022-28886
HistorySep 23, 2022 - 7:15 p.m.

CVE-2022-28886

2022-09-2319:15:11
CWE-835
F-SecureUS
web.nvd.nist.gov
26
4
cve-2022-28886
denial of service
vulnerability
f-secure
withsecure
pe file
scanning engine
nvd

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

23.6%

A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine

Affected configurations

Nvd
Node
f-securecloud_protection_for_salesforce
OR
f-securecollaboration_protection
OR
f-secureelements_endpoint_protectionwindowsx86
OR
f-secureinternet_gatekeeperMatch-
OR
f-securelinux_securityx86
VendorProductVersionCPE
f-securecloud_protection_for_salesforce*cpe:2.3:a:f-secure:cloud_protection_for_salesforce:*:*:*:*:*:*:*:*
f-securecollaboration_protection*cpe:2.3:a:f-secure:collaboration_protection:*:*:*:*:*:*:*:*
f-secureelements_endpoint_protection*cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:windows:x86:*
f-secureinternet_gatekeeper-cpe:2.3:a:f-secure:internet_gatekeeper:-:*:*:*:*:*:*:*
f-securelinux_security*cpe:2.3:a:f-secure:linux_security:*:*:*:*:*:*:x86:*

CNA Affected

[
  {
    "product": "All F-Secure and WithSecure Endpoint Protection products for Windows running 32 bit operating system.  F-Secure Linux Security 32 F-Secure Internet Gatekeeper",
    "vendor": "F-Secure and WithSecure",
    "versions": [
      {
        "status": "affected",
        "version": "All Version "
      }
    ]
  }
]

Social References

More

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

23.6%

Related for CVE-2022-28886