Vulnerability Description
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avira | Anti-Malware Sdk | < 8.3.54.138 |
| Avira | Antivirus Server | < 8.3.54.138 |
| Avira | Avira Antivirus For Endpoint | < 8.3.54.138 |
| Avira | Avira Antivirus For Small Business | < 8.3.54.138 |
| Avira | Avira Exchange Security | < 8.3.54.138 |
| Avira | Avira Free Security Suite | < 8.3.54.138 |
| Avira | Avira Internet Security Suite | < 8.3.54.138 |
| Avira | Avira Prime | < 8.3.54.138 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156472/AVIRA-Generic-Malformed-Container-ByThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Feb/31Mailing ListThird Party Advisory
- https://blog.zoller.lu/p/from-low-hanging-fruit-department-avira.htmlThird Party Advisory
- https://www.zoller.lu/%5BTZO-01-2020%5D%20AVIRA%20Generic%20Bypass%20ISO.pdf
- http://packetstormsecurity.com/files/156472/AVIRA-Generic-Malformed-Container-ByThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Feb/31Mailing ListThird Party Advisory
- https://blog.zoller.lu/p/from-low-hanging-fruit-department-avira.htmlThird Party Advisory
- https://www.zoller.lu/%5BTZO-01-2020%5D%20AVIRA%20Generic%20Bypass%20ISO.pdf
FAQ
What is CVE-2020-9320?
CVE-2020-9320 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Sec...
How severe is CVE-2020-9320?
CVE-2020-9320 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9320?
Check the references section above for vendor advisories and patch information. Affected products include: Avira Anti-Malware Sdk, Avira Antivirus Server, Avira Avira Antivirus For Endpoint, Avira Avira Antivirus For Small Business, Avira Avira Exchange Security.