Vulnerability Description
A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's certificate, which allows an attacker to make MITM SSL connections to an arbitrary site. The product trusts certificates that are issued using the MD5 and SHA1 collision hash functions which allow attackers to create rogue certificates that appear legitimate.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Total Security | < 27.0.25.115 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2023-49567?
CVE-2023-49567 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's certificate, which allows an attacker to make MITM SS...
How severe is CVE-2023-49567?
CVE-2023-49567 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49567?
Check the references section above for vendor advisories and patch information. Affected products include: Bitdefender Total Security.