CVE-2019-8286
Severity:
MEDIUM
Type:
CWE-200
Information Leak / Disclosure
Publication date:
18/07/2019
Last modified:
26/07/2019
Description
Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
Medium
Vulnerable products and versions
- cpe:2.3:a:kaspersky:total_security:*:*:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:anti-virus:*:*:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:internet_security:*:*:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:free_anti-virus:*:*:*:*:*:*:*:*
- cpe:2.3:a:kaspersky:small_office_security:*:*:*:*:*:*:*:*
To consult the complete list of products and versions see this page
References to Advisories, Solutions, and Tools
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#110719 (Source:CONFIRM)
- http://www.securityfocus.com/bid/109300 (Source:BID)