WithSecure (formerly F-Secure)
First CVE: Jun 21, 2021Active for: 5 years
46
CVEs Published
More CVEs Published than 55% of tracked CNAs
23.0
Avg CVEs / Year
More Avg CVEs / Year than 71% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by WithSecure (formerly F-Secure) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2021
5 years ago
Most Recent CVE
Oct 12, 2022
1,380 days ago
Top CVEs
All CVEs published by WithSecure (formerly F-Secure) as a CNA, regardless of affected vendor or product.
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44749CRITICAL A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection | Mar 6, 2022 | 9.6 | 30 | NO | NO |
CVE-2022-28872HIGH A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not corr | May 12, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-40830HIGH The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handsha | Nov 23, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-40829HIGH Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.12.7) and Node.js (versions prio | Nov 23, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-40828HIGH Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions pri | Nov 23, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33601HIGH A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that cou | Sep 28, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-28887HIGH Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible | Oct 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28884HIGH A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that t | Sep 6, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28874HIGH Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and | May 23, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28871HIGH A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scanning larger packages/fuzzed file | Apr 25, 2022 | 7.5 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA46 CVEs
50%
43%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (15.2%)
Network36 (78.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (6.5%)
Attack Complexity
Low46 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (52.2%)
Unknown0 (0.0%)
Required22 (47.8%)
Privileges Required
Low7 (15.2%)
High2 (4.3%)
None37 (80.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by WithSecure (formerly F-Secure) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by WithSecure (formerly F-Secure) as a CNA — matched by CVE ID, not by organization name.