Description
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Published: 2021-06-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

An automatic update to version 25.0.7.29 fixes the issue.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-7717 Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
History

No history.

Subscriptions

Bitdefender Antivirus Plus Internet Security Total Security
cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2024-09-17T01:16:57.105Z

Reserved: 2020-07-14T00:00:00.000Z

Link: CVE-2020-15732

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-22T15:15:08.377

Modified: 2024-11-21T05:06:06.880

Link: CVE-2020-15732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses