# CVE-2024-20380

## Summary

- **CVE ID:** CVE-2024-20380
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-475
- **Published:** Apr 18, 2024
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

## Affected Products

- Cisco — ClamAV ( 1.3)

## References

- [CNA](https://blog.clamav.net/2024/04/clamav-131-123-106-patch-versions.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.10%
- **EPSS Percentile:** 63.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._