Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wg4-cjhf-qgvp

Опубликовано: 18 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.4

Описание

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.

EPSS

Процентиль: 31%
0.0012
Низкий

8.6 High

CVSS4

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
nvd
больше 1 года назад

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.

EPSS

Процентиль: 31%
0.0012
Низкий

8.6 High

CVSS4

7.4 High

CVSS3

Дефекты

CWE-295