Impact
A vulnerability in the PESpin file format permits an unauthenticated file that triggers an out-of-bounds buffer write, leading to memory corruption. The fault causes the ClamAV scanning process to terminate, producing a denial‑of‑service condition The weakness is a classic buffer overflow, identified as CWE‑120, and no additional impacts have been validated beyond the potential DoS mentioned in the advisory.
Affected Systems
Cisco Secure Endpoint deployments that bundle the ClamAV scanner are potentially affected, as the PESpin parsing logic resides within the bundled antivirus component. No specific firmware or software version numbers are disclosed, so all installations containing the bundled ClamAV scanner should be considered at risk until a patched build is available.
Risk and Exploitability
The CVSS score of 7.5 classifies this vulnerability as high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability can be triggered remotely and without authentication by submitting a malicious PESpin file that is subsequently scanned by the ClamAV vector is a remote, file‑submission scenario. Although the vulnerability is not listed in the CISA KEV catalog, the potential for service interruption warrants prompt remediation.
OpenCVE Enrichment
Ubuntu USN