search cancel

Symantec Security Advisory for CVE-2022-37454

book

Article ID: 253681

calendar_today

Updated On:

Products

ProxySG Software - SGOS Web Isolation Cloud Web Security Service - WSS

Issue/Introduction

https://nvd.nist.gov/vuln/detail/CVE-2022-37454

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Resolution

The following products have been investigated and are determined not to be vulnerable

ProxySG

Web Isolation Cloud

Web Security Services (WSS)