Lucene search

K
cvelistBitdefenderCVELIST:CVE-2020-15733
HistoryDec 14, 2020 - 5:05 p.m.

CVE-2020-15733 URL Spoofing Vulnerability in Bitdefender SafePay (VA-8958)

2020-12-1417:05:26
CWE-346
Bitdefender
www.cve.org
4
origin validation error
bitdefender safepay
url spoofing
cve-2020-15733
vulnerability
web resource misrepresentation

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

56.3%

An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.

CNA Affected

[
  {
    "product": "Antivirus Plus",
    "vendor": "Bitdefender",
    "versions": [
      {
        "lessThan": "25.0.7.29.",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

56.3%

Related for CVELIST:CVE-2020-15733