« Back to list

CVE-2022-28880

Status: ModifiedHigh (7.5)—

A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (8)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-28880",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-28880",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T20:16:20.395125Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-notifications-us@f-secure.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-notifications-us@f-secure.com",
      "affectedData": [
        {
          "vendor": "F-Secure",
          "product": "All F-Secure and WithSecure Endpoint Protection products for Mac F-Secure Linux Security (32-bit) F-Secure Linux Security (64-bit) F-Secure Atlant F-Secure Internet Gatekeeper WithSecure Cloud Protection for Salesforce WithSecure Collaboration Protection",
          "versions": [
            {
              "status": "affected",
              "version": "All Version"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-05T17:15:08.447",
  "references": [
    {
      "url": "https://www.f-secure.com/en/home/support/vulnerability-reward-program/hall-of-fame",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ],
      "source": "cve-notifications-us@f-secure.com"
    },
    {
      "url": "https://www.withsecure.com/en/expertise/people",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ],
      "source": "cve-notifications-us@f-secure.com"
    },
    {
      "url": "https://www.f-secure.com/en/home/support/vulnerability-reward-program/hall-of-fame",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.withsecure.com/en/expertise/people",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker."
    },
    {
      "lang": "es",
      "value": "Se ha detectado una vulnerabilidad de denegación de servicio en F-Secure Atlant y en algunos productos WithSecure durante el escaneo de archivos fuzzed PE32-bit que puede bloquear el motor de escaneo. La explotación puede ser desencadenada remotamente por un atacante"
    }
  ],
  "lastModified": "2026-06-17T04:39:16.317",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f-secure:elements_endpoint_detection_and_response:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F97045C-E576-49D3-9630-072E26F7D64F"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DFC1F94-8A8B-42E2-887B-EE8FB3C9130D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f-secure:atlant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C97DC3C-1B63-4B57-8C62-ACD77D0A3E71"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:cloud_protection_for_salesforce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31ECCE87-B67E-4CA7-91E6-8E71CEA6DA21"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:elements_collaboration_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B107FE0-0F9E-4021-917F-1224F2619339"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:internet_gatekeeper:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88F6E1F2-02DA-48EE-B127-4933CCC80C5C"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:linux_security:*:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "F0152E70-F7A9-4785-8A43-78472F9A2C13"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:linux_security_64:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "360DBC2B-2B93-461E-90C6-60C55FBD87B8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-notifications-us@f-secure.com"
}