CVE-2020-10180
Published Mar 5, 2020
Last updated 3 years ago
Overview
- Description
- The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-436
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:eset:cyber_security:*:*:*:*:*:macos:*:*", "vulnerable": true, "matchCriteriaId": "873A6C9F-D339-492F-9234-727BD59D49AE", "versionEndExcluding": "1294" }, { "criteria": "cpe:2.3:a:eset:cyber_security:*:*:*:*:pro:macos:*:*", "vulnerable": true, "matchCriteriaId": "F948F4A7-7F14-457F-B7F1-C11CCF21442B", "versionEndExcluding": "1294" }, { "criteria": "cpe:2.3:a:eset:mobile_security:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "46BEDBE3-DB0E-4BFE-984F-DA9C1E7ECCB7", "versionEndExcluding": "1294" }, { "criteria": "cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AEBB2951-7954-4F12-954F-835FF21487B3", "versionEndExcluding": "1294" }, { "criteria": "cpe:2.3:a:eset:nod32_antivirus:4:*:*:*:*:linux:*:*", "vulnerable": true, "matchCriteriaId": "BCB077E5-6496-4FA9-A552-692A18B04287" }, { "criteria": "cpe:2.3:a:eset:smart_security:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20D1C7D8-52FB-4DDD-9EA3-81D4452C7947", "versionEndExcluding": "1294" }, { "criteria": "cpe:2.3:a:eset:smart_security:*:*:*:*:premium:*:*:*", "vulnerable": true, "matchCriteriaId": "C5D4AC1D-31F1-40A5-82AB-2250F7667553", "versionEndExcluding": "1294" }, { "criteria": "cpe:2.3:a:eset:smart_tv_security:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14871E5E-3939-421B-837F-BE9CF1416687", "versionEndExcluding": "1294" } ], "operator": "OR" } ] } ]