7.5
CVE-2022-28884
- EPSS 0.46%
- Veröffentlicht 06.09.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:58:07
- Quelle cve-notifications-us@f-secure.
- Teams Watchlist Login
- Unerledigt Login
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Withsecure ≫ Business Suite Version- HwPlatformx86
Withsecure ≫ Elements Endpoint Protection HwPlatformx86
F-secure ≫ Internet Gatekeeper Version- SwPlatform-
F-secure ≫ Linux Security Version- HwPlatformx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.46% | 0.633 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
cve-notifications-us@f-secure.com | 4.3 | 0.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.