CVE-2022-28882
Estado: ModificadaAlta (7.5)—
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-835
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-28882",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve-notifications-us@f-secure.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 0.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-notifications-us@f-secure.com",
"affectedData": [
{
"vendor": "F-Secure and WithSecure",
"product": "All F-Secure and WithSecure Endpoint Protection products for Windows & Mac F-Secure Linux Security (32-bit) F-Secure Linux Security (64-bit) F-Secure Atlant F-Secure Internet Gatekeeper WithSecure Cloud Protection for Salesforce WithSecure Collaboration Protection",
"versions": [
{
"status": "affected",
"version": "All Version"
}
]
}
]
}
],
"published": "2022-08-23T16:15:10.237",
"references": [
{
"url": "https://www.withsecure.com/en/support/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "cve-notifications-us@f-secure.com"
},
{
"url": "https://www.withsecure.com/en/support/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-835"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker."
},
{
"lang": "es",
"value": "Se ha detectado una vulnerabilidad de denegación de servicio (DoS) en los productos F-Secure y WithSecure por la que el archivo aegen.dll entra en un bucle infinito cuando desempaqueta archivos PE. Esto conlleva finalmente a un bloqueo del motor de escaneo. La explotación puede ser desencadenada remotamente por un atacante."
}
],
"lastModified": "2026-06-17T04:39:16.563",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DFC1F94-8A8B-42E2-887B-EE8FB3C9130D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f-secure:atlant:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C97DC3C-1B63-4B57-8C62-ACD77D0A3E71"
},
{
"criteria": "cpe:2.3:a:f-secure:cloud_protection_for_salesforce:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31ECCE87-B67E-4CA7-91E6-8E71CEA6DA21"
},
{
"criteria": "cpe:2.3:a:f-secure:elements_collaboration_protection:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B107FE0-0F9E-4021-917F-1224F2619339"
},
{
"criteria": "cpe:2.3:a:f-secure:internet_gatekeeper:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88F6E1F2-02DA-48EE-B127-4933CCC80C5C"
},
{
"criteria": "cpe:2.3:a:f-secure:linux_security:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "F0152E70-F7A9-4785-8A43-78472F9A2C13"
},
{
"criteria": "cpe:2.3:a:f-secure:linux_security_64:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "360DBC2B-2B93-461E-90C6-60C55FBD87B8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-notifications-us@f-secure.com"
}