A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates issued using the DSA signature algorithm. The product does not properly check the certificate chain, allowing an attacker to establish MITM SSL connections to arbitrary sites using a DSA-signed certificate.
References
Configurations
History
22 Oct 2024, 16:38
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.4 |
22 Oct 2024, 16:00
Type | Values Removed | Values Added |
---|---|---|
First Time |
Bitdefender
Bitdefender total Security |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
CPE | cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:* | |
References | () https://www.bitdefender.com/support/security-advisories/insecure-trust-of-dsa-signed-certificates-in-bitdefender-total-security-https-scanning-va-11166/ - Vendor Advisory |
21 Oct 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
Summary |
|
18 Oct 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-18 08:15
Updated : 2024-10-22 16:38
NVD link : CVE-2023-6057
Mitre link : CVE-2023-6057
CVE.ORG link : CVE-2023-6057
JSON object : View
Products Affected
bitdefender
- total_security
CWE
CWE-295
Improper Certificate Validation