Cisco Secure Endpoint Multiple ClamAV DoS (cisco-sa-clamav-WuuvVd26)

high Nessus Plugin ID 335452

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Secure Endpoint is affected by multiple denial of service vulnerabilities.

- A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software. (CVE-2026-20337)

- A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software. (CVE-2026-20338)

- A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result ofmemory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software. (CVE-2026-20339)

- A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result ofmemory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that contains XAR content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
(CVE-2026-20348)

- A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result ofmemory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software. (CVE-2026-20345)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwu34288, CSCwu59475, CSCwu65985, CSCwu78432, CSCwu99410, CSCwv57797

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu34288

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu59475

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu65985

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu78432

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu99410

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwv57797

http://www.nessus.org/u?20148de3

Plugin Details

Severity: High

ID: 335452

File Name: cisco-sa-clamav-WuuvVd26.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 8/14/2026

Updated: 8/14/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6

Percentile: 96.56

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-20337

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:cisco:secure_endpoint

Patch Publication Date: 8/7/2026

Vulnerability Publication Date: 8/7/2026

Reference Information

CVE: CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348