« Volver al listado

CVE-2022-28886

Estado: ModificadaMedia (5.5)—

A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28886",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-28886",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-22T15:34:58.964193Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-notifications-us@f-secure.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-notifications-us@f-secure.com",
      "affectedData": [
        {
          "vendor": "F-Secure and WithSecure",
          "product": "All F-Secure and WithSecure Endpoint Protection products for Windows running 32 bit operating system.  F-Secure Linux Security 32 F-Secure Internet Gatekeeper",
          "versions": [
            {
              "status": "affected",
              "version": "All Version "
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-23T19:15:11.447",
  "references": [
    {
      "url": "https://www.f-secure.com/en/business/support-and-downloads/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-notifications-us@f-secure.com"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-notifications-us@f-secure.com"
    },
    {
      "url": "https://www.f-secure.com/en/business/support-and-downloads/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.withsecure.com/en/support/security-advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-835"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-835"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine"
    },
    {
      "lang": "es",
      "value": "Se ha detectado una vulnerabilidad de denegación de servicio en los productos F-Secure y WithSecure en la que el archivo aerdl.so/aerdl.dll puede entrar en un bucle infinito cuando son desempaquetados archivos PE. Es posible que esto pueda bloquear el motor de escaneo"
    }
  ],
  "lastModified": "2026-06-17T04:39:17.027",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f-secure:cloud_protection_for_salesforce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31ECCE87-B67E-4CA7-91E6-8E71CEA6DA21"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:collaboration_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FA15CDF-797E-49A0-9643-686EF1B4F5AE"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:windows:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "30FE3885-E51D-44DD-A5D8-0795AE3830BD"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:internet_gatekeeper:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30BDCB44-B304-4A12-86A0-4849FAB25D39"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:linux_security:*:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "F0152E70-F7A9-4785-8A43-78472F9A2C13"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-notifications-us@f-secure.com"
}