CVE-2023-42524

HIGH

Withsecure Client Security - Infinite Loop

Title source: rule
STIX 2.1

Description

Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection for Mac 17 and later, Linux Security 64 12.0 , Linux Protection 12.0, and WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1.

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (7)
withsecure/atlant 1.0.35-1
withsecure/client_security 15
withsecure/elements_endpoint_protection 17
withsecure/email_and_server_security 15
withsecure/linux_protection 12.0
withsecure/linux_security_64 12.0
withsecure/server_security 15
Published Sep 18, 2023
Tracked Since Feb 18, 2026