CVE-2020-15732
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Affected (3)
Products: Bitdefender: Antivirus Plus, Internet Security, Total Security
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.0.7.29 | |
| Before 25.0.7.29 | |
| Before 25.0.7.29 |
References (2)
Source: cve-requests@bitdefender.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.