Vulnslist

find the latest Cisco vulnerabilities

ClamAV Truncated File Denial of Service Vulnerability Affecting Cisco Products: May 2022

cisco-sa-clamav-dos-vL9x58p4 · Medium · Published · Updated

On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-vL9x58p4

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2022-20796
Cisco Bug IDsCSCwb13949, CSCwa85589, CSCwb13945
CVSS ScoreBase 6.5
Base 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Secure Endpoint

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Secure Endpoint known_affected cisco_csaf CVE-2022-20796 1

Related Products

Product CVE Evidence
Cisco Secure Endpoint CVE-2022-20796 Cisco OpenVuln