CVE-2021-40837
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/02/2022
Last modified:
11/02/2022
Description
A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:f-secure:atlant:*:*:*:*:*:*:*:* | 2022-02-01_01 (excluding) | |
| cpe:2.3:a:f-secure:internet_gatekeeper:*:*:*:*:*:*:*:* | 2022-02-01_01 (excluding) | |
| cpe:2.3:a:f-secure:linux_security:*:*:*:*:*:*:*:* | 2022-02-01_01 (excluding) | |
| cpe:2.3:a:f-secure:security_cloud:*:*:*:*:*:*:*:* | 2022-02-01_01 (excluding) | |
| cpe:2.3:a:f-secure:elements_endpoint_detection_and_response:*:*:*:*:*:*:*:* | 2022-02-01_01 (excluding) | |
| cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:* | 2022-02-01_01 (excluding) | |
| cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



