CVE-2020-9320
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product
Published:Feb 20, 2020
Last Modified:Nov 21, 2024
EPS:Feb 20, 2020
EPSS Score:0.00625
CVSS Score:5.5
Affected Products
Vendor
Product
Action
Vendor
Avira
Product
Anti-malware Sdk
Avira
Anti-malware Sdk
Vendor
Avira
Product
Antivirus Server
Avira
Antivirus Server
Vendor
Avira
Product
Avira Antivirus For Endpoint
Avira
Avira Antivirus For Endpoint
Vendor
Avira
Product
Avira Antivirus For Small Business
Avira
Avira Antivirus For Small Business
Vendor
Avira
Product
Avira Exchange Security
Avira
Avira Exchange Security
Vendor
Avira
Product
Avira Free Security Suite
Avira
Avira Free Security Suite
Vendor
Avira
Product
Avira Internet Security Suite
Avira
Avira Internet Security Suite
Vendor
Avira
Product
Avira Prime
Avira
Avira Prime
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
