CVE-2021-40832: Denial-of-Service (DoS) Vulnerability
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure systems receive the Capricorn update published via the automatic update channel: Capricorn update 2021-09-29_03, which addresses the AVRDL unpacking module DoS vulnerability.
Event History
Frequently Asked Questions
What is CVE-2021-40832?
CVE-2021-40832 is a Denial-of-Service (DoS) vulnerability discovered in F-Secure Atlant.
Which products are affected by CVE-2021-40832?
The following F-Secure products are affected: F-Secure Atlant, F-Secure Cloud Protection For Salesforce, F-Secure Elements For Microsoft 365, F-Secure Internet Gatekeeper, F-Secure Linux Security, F-Secure Elements Endpoint Detection And Response, F-Secure Elements Endpoint Protection.
How can CVE-2021-40832 be exploited?
CVE-2021-40832 can be exploited remotely by an attacker.
What is the severity of CVE-2021-40832?
CVE-2021-40832 has a severity rating of 6.5 (medium).
Where can I find more information about CVE-2021-40832?
More information about CVE-2021-40832 can be found on the F-Secure website: [https://www.f-secure.com/en/business/support-and-downloads/security-advisories/cve-2021-40832](https://www.f-secure.com/en/business/support-and-downloads/security-advisories/cve-2021-40832)