First published: Tue Jun 22 2021(Updated: )
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender Antivirus Plus | <25.0.7.29 | |
BitDefender Internet Security | <25.0.7.29 | |
Bitdefender Total Security | <25.0.7.29 |
An automatic update to version 25.0.7.29 fixes the issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-15732 is high, with a severity value of 7.5.
CVE-2020-15732 affects Bitdefender Total Security versions prior to 25.0.7.29.
The vulnerability in Bitdefender Total Security is an Improper Certificate Validation vulnerability in the Online Threat Prevention module.
An attacker can potentially bypass HTTP Strict Transport Security (HSTS) checks using CVE-2020-15732.
To fix CVE-2020-15732 in Bitdefender Total Security, update to version 25.0.7.29 or later.