Vulnerability Description
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Total Security | < 27.0.25.115 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2023-6056?
CVE-2023-6056 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificate...
How severe is CVE-2023-6056?
CVE-2023-6056 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6056?
Check the references section above for vendor advisories and patch information. Affected products include: Bitdefender Total Security.