CVE-2020-9320
Published Feb 20, 2020
Last updated 3 months ago
Overview
- Description
- Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product
- Source
- cve@mitre.org
- NVD status
- Modified
- CNA Tags
- disputed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-434
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:avira:anti-malware_sdk:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B72788C-6ACD-482D-87D3-C334D8A16439", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:antivirus_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30F53D27-BB74-4081-ADCD-40E3BCF4CF61", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:avira_antivirus_for_endpoint:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82507BF4-1F45-42B6-85A0-85F3F8D67C82", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:avira_antivirus_for_small_business:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B79CE7D-B721-4020-B203-A41F8756E818", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:avira_exchange_security:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F86DF45-AAF9-456A-8E99-7B79790BC859", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:avira_free_security_suite:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "A136E43F-2878-49EC-9F72-97DD4F9DF509", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:avira_internet_security_suite:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "1E2E63E2-1AC6-463A-B20E-C73B51F1C3EF", "versionEndExcluding": "8.3.54.138" }, { "criteria": "cpe:2.3:a:avira:avira_prime:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10E837C1-A5D3-48CC-8E0E-AE4D99AD7CFA", "versionEndExcluding": "8.3.54.138" } ], "operator": "OR" } ] } ]