CVE-2023-6056

Severity CVSS v4.0:
HIGH
Type:
CWE-295 Improper Certificate Validation
Publication date:
18/10/2024
Last modified:
22/10/2024

Description

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:* 27.0.25.115 (excluding)