CVE-2023-6056: Bitdefender Total Security
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to establish MITM SSL connections to arbitrary sites.
Affected products
- Bitdefender Total Security: before 27.0.25.115 (fixed in 27.0.25.115)
Published 2024-10-18. Last modified 2026-06-17.