Lucene search

K
cveMitreCVE-2020-8987
HistoryMar 09, 2020 - 5:15 p.m.

CVE-2020-8987

2020-03-0917:15:12
CWE-295
mitre
web.nvd.nist.gov
202
avast
avg
antitrack
cve-2020-8987
mitm
https
certificate validation
security vulnerability

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

37.0%

Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using AntiTrack with “Allow filtering of HTTPS traffic for tracking detection” enabled. (This is the default configuration.)

Affected configurations

Nvd
Node
avastantitrackRange<1.5.1.172
OR
avastavg_antitrackRange<2.0.0.178
VendorProductVersionCPE
avastantitrack*cpe:2.3:a:avast:antitrack:*:*:*:*:*:*:*:*
avastavg_antitrack*cpe:2.3:a:avast:avg_antitrack:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

37.0%

Related for CVE-2020-8987