Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c2q-v642-37w6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway.

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway.

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-436

Связанные уязвимости

CVSS3: 7.8
nvd
почти 6 лет назад

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-436