CVE-2020-9320
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
20/02/2020
Last modified:
04/08/2024
Description
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:avira:anti-malware_sdk:*:*:*:*:*:*:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:antivirus_server:*:*:*:*:*:*:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:avira_antivirus_for_endpoint:*:*:*:*:*:*:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:avira_antivirus_for_small_business:*:*:*:*:*:*:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:avira_exchange_security:*:*:*:*:*:*:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:avira_free_security_suite:*:*:*:*:*:windows:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:avira_internet_security_suite:*:*:*:*:*:windows:*:* | 8.3.54.138 (excluding) | |
cpe:2.3:a:avira:avira_prime:*:*:*:*:*:*:*:* | 8.3.54.138 (excluding) |
To consult the complete list of CPE names with products and versions, see this page