CVE-2022-28874
Multiple Denial-of-Service (DoS) Vulnerabilities
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.
Se han detectado múltiples vulnerabilidades de Denegación de Servicio en F-Secure Atlant y en determinados productos WithSecure mientras son escaneados archivos PE32-bit fuzzed que causan corrupción de memoria y desbordamiento de búfer de la pila, lo que eventualmente puede bloquear el motor de escaneo. La explotación puede ser desencadenada remotamente por un atacante
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-04-08 CVE Reserved
- 2022-05-23 CVE Published
- 2023-12-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.withsecure.com/en/support/security-advisories | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.f-secure.com/en/home/support/security-advisories | 2022-06-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F-secure Search vendor "F-secure" | Atlant Search vendor "F-secure" for product "Atlant" | * | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
F-secure Search vendor "F-secure" | Atlant Search vendor "F-secure" for product "Atlant" | * | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
F-secure Search vendor "F-secure" | Elements Endpoint Protection Search vendor "F-secure" for product "Elements Endpoint Protection" | * | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
F-secure Search vendor "F-secure" | Elements Endpoint Protection Search vendor "F-secure" for product "Elements Endpoint Protection" | * | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
F-secure Search vendor "F-secure" | Linux Security Search vendor "F-secure" for product "Linux Security" | * | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
F-secure Search vendor "F-secure" | Linux Security Search vendor "F-secure" for product "Linux Security" | * | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Withsecure Search vendor "Withsecure" | Cloud Protection For Salesforce Search vendor "Withsecure" for product "Cloud Protection For Salesforce" | * | - |
Affected
| ||||||
Withsecure Search vendor "Withsecure" | Elements Collaboration Protection Search vendor "Withsecure" for product "Elements Collaboration Protection" | * | - |
Affected
|