7.8
CVE-2023-6154
- EPSS 0.05%
- Veröffentlicht 01.04.2024 11:15:52
- Zuletzt bearbeitet 07.02.2025 16:52:05
- Quelle cve-requests@bitdefender.com
- Teams Watchlist Login
- Unerledigt Login
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total Security: 27.0.25.114; Internet Security: 27.0.25.114; Antivirus Plus: 27.0.25.114; Antivirus Free: 27.0.25.114.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitdefender ≫ Antivirus Version27.0.25.114 SwEditionfree
Bitdefender ≫ Antivirus Plus Version27.0.25.114
Bitdefender ≫ Internet Security Version27.0.25.114
Bitdefender ≫ Total Security Version27.0.25.114
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.138 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
cve-requests@bitdefender.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-15 External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
CWE-610 Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.