Impact
The vulnerability arises from an integer overflow in the PESpin file format parser within ClamAV. Improper boundary checks when reading PESpin content may corrupt memory, potentially causing the scanning process to terminate. A successful exploit yields a denial‑of‑service condition on the affected device, with the possibility of additional impacts if memory corruption is leveraged further.
Affected Systems
Cisco Secure Endpoint is the verified affected product. Exact impacted version ranges are not disclosed in the advisory, so administrators of Cisco Secure Endpoint should verify whether their deployments include the vulnerable parser and consult Cisco's documentation for specific version guidance.
Risk and Exploitability
The CVSS score of 7.5 classifies this weakness as high severity. EPSS is not available, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in CISA's KEV catalog, indicating no documented widespread exploitation yet, but the remote, unauthenticated attack vector inferred from the description suggests that an attacker could deliver a crafted PESpin file over the network to trigger the overflow. In the absence of an official fix, the risk remains significant until a patch or mitigative configuration is applied.
OpenCVE Enrichment