Lucene search

K
cveMitreCVE-2020-9320
HistoryFeb 20, 2020 - 10:15 p.m.

CVE-2020-9320

2020-02-2022:15:12
CWE-434
mitre
web.nvd.nist.gov
71
2
avira
antivirus
endpoint
small business
exchange security
internet security
prime
free security
cross platform anti-malware
vulnerability
cve-2020-9320
iso archive
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

29.1%

Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product

Affected configurations

Nvd
Node
aviraanti-malware_sdkRange<8.3.54.138
OR
aviraantivirus_serverRange<8.3.54.138
OR
aviraavira_antivirus_for_endpointRange<8.3.54.138
OR
aviraavira_antivirus_for_small_businessRange<8.3.54.138
OR
aviraavira_exchange_securityRange<8.3.54.138
OR
aviraavira_free_security_suiteRange<8.3.54.138windows
OR
aviraavira_internet_security_suiteRange<8.3.54.138windows
OR
aviraavira_primeRange<8.3.54.138
VendorProductVersionCPE
aviraanti-malware_sdk*cpe:2.3:a:avira:anti-malware_sdk:*:*:*:*:*:*:*:*
aviraantivirus_server*cpe:2.3:a:avira:antivirus_server:*:*:*:*:*:*:*:*
aviraavira_antivirus_for_endpoint*cpe:2.3:a:avira:avira_antivirus_for_endpoint:*:*:*:*:*:*:*:*
aviraavira_antivirus_for_small_business*cpe:2.3:a:avira:avira_antivirus_for_small_business:*:*:*:*:*:*:*:*
aviraavira_exchange_security*cpe:2.3:a:avira:avira_exchange_security:*:*:*:*:*:*:*:*
aviraavira_free_security_suite*cpe:2.3:a:avira:avira_free_security_suite:*:*:*:*:*:windows:*:*
aviraavira_internet_security_suite*cpe:2.3:a:avira:avira_internet_security_suite:*:*:*:*:*:windows:*:*
aviraavira_prime*cpe:2.3:a:avira:avira_prime:*:*:*:*:*:*:*:*

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

29.1%

Related for CVE-2020-9320