Vulnerability CVE-2023-6056


Published: 2024-10-18

Description:
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.

Type:

CWE-295

(Certificate Issues)

 References:
https://www.bitdefender.com/support/security-advisories/insecure-trust-of-self-signed-certificates-in-bitdefender-total-security-https-scanning-va-11164/

Copyright 2024, cxsecurity.com

 

Back to Top