CVE-2022-45871: Denial-of-Service (DoS) Vulnerability
Published Dec 13, 2022
·Updated
A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing ICAP request. The exploit can be triggered remotely by an attacker.
Affected Software
1 affected component
F-Secure Atlant
Remediation
Information
FIX No User action is required. The required fix has been published through automatic update channel with BaseGuard version 1.0.723 on 2022-11-28
Please note : User action is needed, if you are running pinned Atlant version.
Event History
Dec 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverity
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-45871.
2
What is the severity rating of CVE-2022-45871?
CVE-2022-45871 has a severity rating of 7.5 (high).
3
Which software is affected by CVE-2022-45871?
CVE-2022-45871 affects F-Secure Atlant.
4
How does the vulnerability manifest?
The vulnerability allows remote attackers to crash the fsicapd component in WithSecure products while parsing ICAP request, resulting in a Denial-of-Service (DoS) condition.
5
Is there a fix available for CVE-2022-45871?
Please refer to the vendor's security advisory for information on available fixes.