7.5
CVE-2022-28884
- EPSS 0.46%
- Published 06.09.2022 18:15:12
- Last modified 21.11.2024 06:58:07
- Source cve-notifications-us@f-secure.
- Teams watchlist Login
- Open Login
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
Data is provided by the National Vulnerability Database (NVD)
Withsecure ≫ Business Suite Version- HwPlatformx86
Withsecure ≫ Elements Endpoint Protection HwPlatformx86
F-secure ≫ Internet Gatekeeper Version- SwPlatform-
F-secure ≫ Linux Security Version- HwPlatformx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.46% | 0.633 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
cve-notifications-us@f-secure.com | 4.3 | 0.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.