MEDIUM · 5.5

CVE-2021-27506

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 t...

Vulnerability Description

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Netasq ProjectNetasq>= 9.1.0, <= 9.1.11
StormshieldStormshield Network Security>= 1.0, <= 4.2.0
ClamavClamav<= 0.103.1

References

FAQ

What is CVE-2021-27506?

CVE-2021-27506 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 t...

How severe is CVE-2021-27506?

CVE-2021-27506 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-27506?

Check the references section above for vendor advisories and patch information. Affected products include: Netasq Project Netasq, Stormshield Stormshield Network Security, Clamav Clamav.