Vulnerability Description
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F-Secure | Elements Endpoint Protection | All versions |
| Apple | Macos | - |
| Microsoft | Windows | - |
| F-Secure | Atlant | All versions |
| F-Secure | Cloud Protection For Salesforce | All versions |
| F-Secure | Elements Collaboration Protection | All versions |
| F-Secure | Internet Gatekeeper | All versions |
| F-Secure | Linux Security | All versions |
| F-Secure | Linux Security 64 | All versions |
References
- https://www.withsecure.com/en/support/security-advisoriesVendor Advisory
- https://www.withsecure.com/en/support/security-advisoriesVendor Advisory
FAQ
What is CVE-2022-28883?
CVE-2022-28883 is a vulnerability with a CVSS score of 3.5 (LOW). A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can b...
How severe is CVE-2022-28883?
CVE-2022-28883 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28883?
Check the references section above for vendor advisories and patch information. Affected products include: F-Secure Elements Endpoint Protection, Apple Macos, Microsoft Windows, F-Secure Atlant, F-Secure Cloud Protection For Salesforce.