VYPR
Medium severity6.8NVD Advisory· Published Oct 18, 2024· Updated Jun 17, 2026

CVE-2023-49567

CVE-2023-49567

Description

A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's certificate, which allows an attacker to make MITM SSL connections to an arbitrary site. The product trusts certificates that are issued using the MD5 and SHA1 collision hash functions which allow attackers to create rogue certificates that appear legitimate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Bitdefender/Total Securityllm-fuzzy3 versions
    (expand)+ 2 more
    • (no CPE)
    • (no CPE)range: 0
    • cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:*range: <27.0.25.115

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.