Vulnerability Name: | CVE-2021-27506 (CCN-198469) | ||||||||||||
Assigned: | 2021-02-19 | ||||||||||||
Published: | 2021-02-19 | ||||||||||||
Updated: | 2022-07-01 | ||||||||||||
Summary: | The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
4.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-27506 Source: CCN Type: Stormshield Web site Stormshield Network Security Source: CONFIRM Type: Broken Link, Vendor Advisory https://advisories.stormshield.eu/2021-003/ Source: MISC Type: Vendor Advisory https://blog.clamav.net/2021/02/clamav-01031-patch-release.html Source: XF Type: UNKNOWN stormshield-cve202127506-dos(198469) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
BACK |