CVE Explorer
CVE-2026-20215
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.
This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z content to be scanned by ClamAV on
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Cisco Secure Endpoint","vendor":"Cisco","versions":[{"status":"affected","version":"7.0.5"},{"status":"affected","version":"6.2.19"},{"status":"affected","version":"7.3.3"},{"status":"affected","version":"7.2.13"},{"status":"affected","version":"6.1.5"},{"status":"affected","version":"6.3.1"},{"status":"affected","version":"6.2.5"},{"status":"affected","version":"7.3.5"},{"status":"affected","version":"6.2.1"},{"status":"affected","version":"7.2.7"},{"status":"affected","version":"7.1.1"},{"status":"affected","version":"6.3.5"},{"status":"affected","versio…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d563f8e7fd4fa5d9673fdeb7461020be49aec007234a79690ac7d3b234b9539a · sha256:88532d6a2d682bc6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d563f8e7fd4fa5d9673fdeb7461020be49aec007234a79690ac7d3b234b9539a · sha256:88532d6a2d682bc6… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-120","description":"Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d563f8e7fd4fa5d9673fdeb7461020be49aec007234a79690ac7d3b234b9539a · sha256:88532d6a2d682bc6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"cisco-sa-clamav-88cFYyxR","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d563f8e7fd4fa5d9673fdeb7461020be49aec007234a79690ac7d3b234b9539a · sha256:88532d6a2d682bc6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.