Lucene search

K
cveBitdefenderCVE-2020-15733
HistoryDec 14, 2020 - 5:15 p.m.

CVE-2020-15733

2020-12-1417:15:11
CWE-346
Bitdefender
web.nvd.nist.gov
22
2
cve-2020-15733
origin validation error
bitdefender antivirus plus
safepay component
vulnerability
nvd
security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

56.3%

An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.

Affected configurations

Nvd
Node
bitdefenderantivirus_plusRange<25.0.7.29
VendorProductVersionCPE
bitdefenderantivirus_plus*cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Antivirus Plus",
    "vendor": "Bitdefender",
    "versions": [
      {
        "lessThan": "25.0.7.29.",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

56.3%

Related for CVE-2020-15733