Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-10180


The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.


Published

2020-03-05T19:15:11.467

Last Modified

2024-11-21T04:54:55.220

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-436

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset cyber_security < 1294 Yes
Application eset cyber_security < 1294 Yes
Application eset mobile_security < 1294 Yes
Application eset nod32_antivirus < 1294 Yes
Application eset nod32_antivirus 4 Yes
Application eset smart_security < 1294 Yes
Application eset smart_security < 1294 Yes
Application eset smart_tv_security < 1294 Yes

References