CVE-2023-49567: Insecure Trust of certificates using collision hash functions in Bitdefender Total Security HTTPS Scanning (VA-11239)
A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's certificate, which allows an attacker to make MITM SSL connections to an arbitrary site. The product trusts certificates that are issued using the MD5 and SHA1 collision hash functions which allow attackers to create rogue certificates that appear legitimate.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49567?
CVE-2023-49567 has been classified as a high severity vulnerability due to its ability to facilitate man-in-the-middle SSL attacks.
How do I fix CVE-2023-49567?
To fix CVE-2023-49567, users should update their Bitdefender Total Security to the latest version available beyond 27.0.25.115.
What is the impact of CVE-2023-49567?
The impact of CVE-2023-49567 allows attackers to establish HTTPS connections to arbitrary sites by exploiting incorrect certificate checks.
Which versions of Bitdefender Total Security are affected by CVE-2023-49567?
Versions of Bitdefender Total Security prior to 27.0.25.115 are affected by CVE-2023-49567.
How can attackers exploit CVE-2023-49567?
Attackers can exploit CVE-2023-49567 by leveraging the vulnerability to bypass SSL certificate validation, leading to potential data interception.