Description
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.

This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Published: 2026-08-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an integer overflow in the PESpin file format parser within ClamAV. Improper boundary checks when reading PESpin content may corrupt memory, potentially causing the scanning process to terminate. A successful exploit yields a denial‑of‑service condition on the affected device, with the possibility of additional impacts if memory corruption is leveraged further.

Affected Systems

Cisco Secure Endpoint is the verified affected product. Exact impacted version ranges are not disclosed in the advisory, so administrators of Cisco Secure Endpoint should verify whether their deployments include the vulnerable parser and consult Cisco's documentation for specific version guidance.

Risk and Exploitability

The CVSS score of 7.5 classifies this weakness as high severity. EPSS is not available, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in CISA's KEV catalog, indicating no documented widespread exploitation yet, but the remote, unauthenticated attack vector inferred from the description suggests that an attacker could deliver a crafted PESpin file over the network to trigger the overflow. In the absence of an official fix, the risk remains significant until a patch or mitigative configuration is applied.

Generated by OpenCVE AI on August 7, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade Cisco Secure Endpoint to a version that fixes the PESpin parser integer overflow
  • If a patch is unavailable, block or disable PESpin file processing to prevent DoS
  • Monitor scanning processes for abnormal termination and audit information for signs of memory corruption

Generated by OpenCVE AI on August 7, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Title ClamAV PESpin File Format Processing Integer Overflow Vulnerability
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-07T16:42:33.962Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20339

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T17:30:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound