CVE-2023-20197 is a high-severity denial-of-service vulnerability in ClamAV's HFS+ filesystem image parser, affecting Cisco Secure Endpoint and Fedora products. An unauthenticated, remote attacker can exploit an incorrect decompression completion check by submitting a crafted HFS+ image, causing the scanning process to loop indefinitely and consume system resources. With a CVSS score of 7.5, this vulnerability requires no user interaction and has a high impact on availability. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:* | ||
< 1.22.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:* | ||
< 7.5.13.21586CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:* | ||
>= 8.0.1.21160, < 8.1.7.21585CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:* | ||
< 3.8.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.