CVE-2022-28871: Denial-of-Service (DoS) Vulnerability
Published Apr 25, 2022
·Updated
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scanning larger packages/fuzzed files consume too much memory eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.
Affected Software
4 affected components
F-Secure Atlant
Apple iOS and macOS
Apple macOS
Microsoft Windows
Remediation
Information
FIX No User action is required. The required fix has been published through automatic update channel with HydraLinux update 2022-04-12_01
Event History
Apr 25, 2022
CVE Published
via MITRE·10:14 AM
Data Sourced
via MITRE·10:14 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Denial-of-Service (DoS) vulnerability?
The vulnerability ID for this Denial-of-Service (DoS) vulnerability is CVE-2022-28871.
2
What is the severity level of CVE-2022-28871?
The severity level of CVE-2022-28871 is high, with a severity value of 7.5.
3
Which software is affected by CVE-2022-28871?
The F-Secure Atlant software is affected by CVE-2022-28871.
4
How can this vulnerability be exploited?
This vulnerability can be exploited remotely by an attacker.
5
Are Apple Mac OS X, Apple macOS, and Microsoft Windows affected by CVE-2022-28871?
No, Apple Mac OS X, Apple macOS, and Microsoft Windows are not affected by CVE-2022-28871.