A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.
2024-10-18T08:15:03.500
2024-10-22T16:38:43.993
Analyzed
CVSSv3.1: 7.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bitdefender | total_security | < 27.0.25.115 | Yes |