CVE-2020-9320

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/02/2020
Last modified:
04/08/2024

Description

Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avira:anti-malware_sdk:*:*:*:*:*:*:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:antivirus_server:*:*:*:*:*:*:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:avira_antivirus_for_endpoint:*:*:*:*:*:*:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:avira_antivirus_for_small_business:*:*:*:*:*:*:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:avira_exchange_security:*:*:*:*:*:*:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:avira_free_security_suite:*:*:*:*:*:windows:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:avira_internet_security_suite:*:*:*:*:*:windows:*:* 8.3.54.138 (excluding)
cpe:2.3:a:avira:avira_prime:*:*:*:*:*:*:*:* 8.3.54.138 (excluding)