• News/
  • https://www.bleepingcomputer.com/news/security/cisco-warns-of-denial-of-service-flaw-with-poc-exploit-code/

Cisco warns of denial of service flaw with PoC exploit code

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 22, 2025
·
Updated

Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code. Tracked as CVE-2025-20128, the vulnerability is caused by a heap-based buffer overflow weakness in the Object Linking and Embedding 2 (OLE2) decryption routine, allowing unauthenticated, remote attackers to trigger a DoS condition on vulnerable devices. If this vulnerability is successfully exploited, it could cause the ClamAV antivirus scanning process to crash, preventing or delaying further scanning operations. "An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device," Cisco explained. "A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software." However, in an advisory issued today, the company noted that overall system stability would not be affected even after successful attacks. The vulnerable products list includes the Secure Endpoint Connector software for Linux, Mac, and Windows-based platforms. This solution helps ingest Cisco Secure Endpoint audit logs and events into security information and event management (SIEM) systems like Microsoft Sentinel. While the Cisco Product Security Incident Response Team (PSIRT) said it has no evidence of in-the-wild exploitation, it added that CVE-2025-20128 exploit code is already available. "The Cisco PSIRT is aware that p...

Read full article

Affected Software

8 affected components
Cisco ClamAV
Cisco Secure Endpoint Connector
Cisco Cisco BroadWorks
Cisco Cisco Meeting Management
Cisco ASA
Cisco Firepower Threat Defense (FTD)
Cisco Ultra-Reliable Wireless Backhaul (URWB)
Cisco ClamAV
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a denial-of-service vulnerability in Cisco's ClamAV software, which has been assigned the identifier CVE-2025-20128.

2

What security implications are discussed?

The article highlights that the vulnerability could be exploited to cause a denial-of-service condition, impacting the availability of affected systems.

3

What products or software are affected?

The affected products include Cisco ClamAV, Cisco Secure Endpoint Connector, Cisco BroadWorks, Cisco Meeting Management, Cisco ASA, and Cisco Firepower Threat Defense.

4

Is there a patch available for the vulnerability?

Yes, Cisco has released security updates to patch the ClamAV denial-of-service vulnerability.

5

What type of vulnerability is CVE-2025-20128?

CVE-2025-20128 is categorized as a heap-based buffer overflow vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203