CVE Vulnerabilities

CVE-2023-49570

Improper Certificate Validation

Published: Oct 18, 2024 | Modified: Oct 22, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isnt authorized to issue certificates. This occurs when the Basic Constraints extension in the certificate indicates that it is meant to be an End Entity”. This flaw could allow an attacker to perform a Man-in-the-Middle (MITM) attack, intercepting and potentially altering communications between the user and the website.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Total_securityBitdefender*27.0.25.115 (excluding)

Potential Mitigations

References