CVE Vulnerabilities

CVE-2023-49570

Improper Certificate Validation

Published: Oct 18, 2024 | Modified: Oct 22, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isnt authorized to issue certificates. This occurs when the Basic Constraints extension in the certificate indicates that it is meant to be an End Entityā€¯. This flaw could allow an attacker to perform a Man-in-the-Middle (MITM) attack, intercepting and potentially altering communications between the user and the website.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Total_security Bitdefender * 27.0.25.115 (excluding)

Potential Mitigations

References