A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.
References
Configurations
History
No history.
Information
Published : 2024-10-18 08:15
Updated : 2024-10-22 16:38
NVD link : CVE-2023-6056
Mitre link : CVE-2023-6056
CVE.ORG link : CVE-2023-6056
JSON object : View
Products Affected
bitdefender
- total_security
CWE
CWE-295
Improper Certificate Validation