CVE-2020-25289: Medium severity avast secureline vpn vulnerability
Published Sep 13, 2020
·Updated
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
Affected Software
1 affected component
Avast Secureline Vpn<5.6.4982.470
Event History
Sep 13, 2020
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this AVAST SecureLine VPN vulnerability?
The vulnerability ID for this AVAST SecureLine VPN vulnerability is CVE-2020-25289.
2
What is the severity of CVE-2020-25289?
The severity of CVE-2020-25289 is medium with a CVSS score of 5.5.
3
How does CVE-2020-25289 impact AVAST SecureLine VPN?
CVE-2020-25289 allows local users to write to arbitrary files on AVAST SecureLine VPN through a symbolic link from the log directory.
4
Which version of AVAST SecureLine VPN is affected by CVE-2020-25289?
AVAST SecureLine VPN version up to exclusive 5.6.4982.470 is affected by CVE-2020-25289.
5
Is there a fix available for CVE-2020-25289?
Yes, updating AVAST SecureLine VPN to version 5.6.4982.470 or later will fix CVE-2020-25289.