SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27506

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files.

MEDIUM 5.5EPSS 1.31%

Does this matter?

Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.

Description

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
1.31% probability · 69th percentile
CISA KEV
Not listed
Affected
netasq project/netasq · stormshield/stormshield network security · clamav/clamav
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.