← Vulnerability feed

Vulnerability record · CVE-2021-33572 · published 21 June 2021

CVE-2021-33572: F-secure cloud protection for salesforce null pointer dereference vulnerability

F Secure · Cloud Protection For Salesforce

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

6.5 CVSS 3.1 Medium EPSS 0.68% · top 49.4% CWE-476 · NULL pointer dereference
6.5CVSS 3.1 base score, v2 4.0
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33572 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-28887F-secure elements endpoint detection and response improper resource shutdown vulnerabilityMultiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crash…EPSS 0.40%7.5CVE-2022-28884Withsecure business suite vulnerabilityA Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking …EPSS 0.47%7.5CVE-2022-28885F-secure atlant vulnerabilityA Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsi…EPSS 0.47%7.5CVE-2022-28882F-secure elements endpoint protection vulnerabilityA Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unp…EPSS 0.44%7.5CVE-2022-28883F-secure elements endpoint protection vulnerabilityA Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to …EPSS 0.59%7.5CVE-2022-28881F-secure elements endpoint detection and response vulnerabilityA Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacke…EPSS 0.47%7.5CVE-2022-28880F-secure elements endpoint detection and response uncontrolled resource consumption vulnerabilityA Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is…EPSS 0.49%7.5CVE-2022-28879F-secure elements endpoint protection vulnerabilityA Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aepack.dll comp…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2021-33572), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.