Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-7717 Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Fixes

Solution

An automatic update to version 25.0.7.29 fixes the issue.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2024-09-17T01:16:57.105Z

Reserved: 2020-07-14T00:00:00

Link: CVE-2020-15732

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-22T15:15:08.377

Modified: 2024-11-21T05:06:06.880

Link: CVE-2020-15732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.