CVE-2021-27506
Last modified
CVE-2021-27506 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netasq Project | Netasq | >= 9.1.0, <= 9.1.11 |
| Stormshield | Stormshield Network Security | >= 1.0, <= 4.2.0 |
| Clamav | Clamav | <= 0.103.1 |
References
- https://advisories.stormshield.eu/2021-003/Broken Link, Vendor Advisory
- https://advisories.stormshield.eu/2021-003/Broken Link, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27506?
How severe is CVE-2021-27506?
How do I fix CVE-2021-27506?
Are you affected by CVE-2021-27506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
