VYPR
Unrated severityNVD Advisory· Published Jul 22, 2022· Updated Aug 3, 2024

Denial-of-Service (DoS) Vulnerability

CVE-2022-28878

Description

A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed APK file it is possible that can crash the scanning engine.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial-of-service vulnerability in F-Secure Atlant and certain WithSecure products allows crash of the scanning engine when processing a fuzzed APK file.

Vulnerability

A denial-of-service vulnerability exists in the scanning engine of F-Secure Atlant and certain WithSecure products. When scanning a specially crafted (fuzzed) APK file, the engine can crash, leading to a denial of service. The affected versions are not explicitly disclosed in the available references [1][2].

Exploitation

An attacker needs to deliver a malicious APK file to the target system. No authentication is required if the file is scanned automatically (e.g., on-access scanning). The attacker crafts a fuzzed APK that triggers the crash during scanning.

Impact

Successful exploitation causes the scanning engine to crash, resulting in a denial of service. The system may become unprotected until the engine is restarted. No code execution or data compromise is indicated.

Mitigation

F-Secure and WithSecure have likely released updates; however, the specific fixed version is not provided in the available references [1][2]. Users should consult the vendor's advisory pages for the latest patches.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • F-Secure/All F-Secure and WithSecure Endpoint Protection products for Windows & Mac F-Secure Linux Security 64 F-Secure Linux Security 32 F-Secure Atlant F-Secure Internet Gatekeeper WithSecure Cloud Protection for Salesforce WithSecure Collaboration Protectionv5
    Range: All Version

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.