Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Summary
Cisco has issued a warning regarding high-severity vulnerabilities discovered in ClamAV, a widely used open-source antivirus engine. These flaws could allow remote, unauthenticated attackers to trigger a denial-of-service condition on affected systems. A public proof-of-concept (PoC) is available for these vulnerabilities.
IFF Assessment
The discovery of high-severity vulnerabilities with a public proof-of-concept represents a direct threat to systems that utilize ClamAV, as it enables attackers to disrupt services.
Severity
The CVSS score is estimated at 7.5 (High) considering that the vulnerabilities are remotely exploitable by unauthenticated attackers and lead to a denial-of-service condition, which can significantly disrupt operations, although it doesn't directly lead to information disclosure or system compromise.
Defender Context
Defenders should prioritize patching or mitigating systems running ClamAV due to these high-severity vulnerabilities. The existence of a public proof-of-concept increases the risk of exploitation, making timely remediation crucial to prevent denial-of-service attacks. Organizations should monitor for related advisories and ensure their security solutions are up-to-date.