Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20212


A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a crafted AutoIt file to be scanned by ClamAV on the affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to restart unexpectedly, resulting in a DoS condition.


Published

2023-08-18T20:15:09.773

Last Modified

2024-11-21T07:40:53.953

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-825
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco secure_endpoint < 8.1.7.21585 Yes
Application cisco secure_endpoint_private_cloud < 3.8.0 Yes

References