Vulnslist

find the latest Cisco vulnerabilities

ClamAV AutoIt Module Denial of Service Vulnerability

cisco-sa-clamav-dos-FTkhqMWZ · High · Published · Updated

A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a crafted AutoIt file to be scanned by ClamAV on the affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to restart unexpectedly, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. For a description of this vulnerability, see the ClamAV blog. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-FTkhqMWZ

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2023-20212
Cisco Bug IDsCSCwf30972, CSCwf30973
CVSS ScoreBase 7.5
Base 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Secure Endpoint

Related Products

Product CVE Evidence
Cisco Secure Endpoint CVE-2023-20212 Cisco OpenVuln