CVE-2020-3314 describes a denial-of-service vulnerability in Cisco AMP for Endpoints Mac Connector Software, stemming from insufficient input validation during file scans. An attacker can exploit this by providing a crafted file, causing the AMP Connector to crash and restart, leading to missed detections and a potential DoS condition for the service. Rated Medium severity (CVSS 6.1), this vulnerability requires user interaction (UI:R) to deliver the crafted file, but has low attack complexity (AC:L). A successful exploit primarily impacts availability (A:H) by disrupting the AMP service, with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there's limited community discussion and media coverage, the EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.3.738CPE matchmatch criteria | cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints:*:*:*:*:*:mac_os:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.