Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-10193


ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.


Published

2020-03-06T20:15:12.597

Last Modified

2024-11-21T04:54:56.763

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-436

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eset cyber_security < 1294 Yes
Application eset internet_security < 1294 Yes
Application eset mobile_security < 1294 Yes
Application eset mobile_security 1294 Yes
Application eset nod32_antivirus < 4 Yes
Application eset nod32_antivirus < 1294 Yes
Application eset smart_security < 1294 Yes
Application eset smart_tv_security < 1294 Yes

References