Vulnerability Name:

CVE-2020-3350 (CCN-183603)

Assigned:2019-12-12
Published:2020-06-17
Updated:2023-03-03
Summary:
CVSS v3 Severity:6.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H)
5.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2020-3350

Source: XF
Type: UNKNOWN
cisco-cve20203350-priv-esc(183603)

Source: ykramarz@cisco.com
Type: Mailing List, Third Party Advisory
ykramarz@cisco.com

Source: ykramarz@cisco.com
Type: Mailing List, Third Party Advisory
ykramarz@cisco.com

Source: ykramarz@cisco.com
Type: Mailing List, Third Party Advisory
ykramarz@cisco.com

Source: ykramarz@cisco.com
Type: Third Party Advisory
ykramarz@cisco.com

Source: CCN
Type: Cisco Security Advisory cisco-sa-famp-ZEpdXy
Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability

Source: ykramarz@cisco.com
Type: Vendor Advisory
ykramarz@cisco.com

Source: ykramarz@cisco.com
Type: Third Party Advisory
ykramarz@cisco.com

Source: ykramarz@cisco.com
Type: Third Party Advisory
ykramarz@cisco.com

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:clamav:clamav:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7463
    P
    clamav-0.103.8-150000.3.44.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:94472
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3189
    P
    libipa_hbac0-1.16.1-4.17.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3360
    P
    rzsz-0.12.21~rc-1001.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94519
    P
    clamav-0.103.5-3.35.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2889
    P
    clamav-0.103.5-3.35.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:27
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:956
    P
    Security update for expat (Important)
    2022-03-04
    oval:org.opensuse.security:def:112078
    P
    clamav-0.103.3-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105621
    P
    clamav-0.103.3-1.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:96753
    P
    python3-Jinja2-2.10.1-3.5.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:100803
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62045
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101185
    P
    libcdio16-0.94-6.9.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71786
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:38102
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:44491
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:38764
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:45660
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:40061
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:43194
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:41230
    P
    Security update for clamav (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32837
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:82081
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:23876
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:55787
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:89105
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:84540
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:31099
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:21360
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:58660
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:127078
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:51864
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:87301
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:33627
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:82518
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:28874
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:56922
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:89363
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:85563
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:31569
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:23110
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:59450
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:54697
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:88090
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:33885
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:83171
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:29311
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:57392
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:125509
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:51098
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:86033
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:32019
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:81033
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:23496
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:59708
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:55134
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:88399
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:84085
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:29964
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:57842
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:126681
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:51484
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:86483
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:110920
    P
    Security update for clamav (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:110374
    P
    Security update for clamav (Moderate)
    2020-12-17
    oval:org.opensuse.security:def:90427
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:73400
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:117366
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:104082
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:73571
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:64278
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:97392
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:107851
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:64449
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:60153
    P
    Security update for clamav (Important)
    2020-12-09
    oval:org.opensuse.security:def:34330
    P
    Security update for clamav (Important)
    2020-12-09
    BACK
    clamav clamav *