CVE-2020-9320
Summary
| CVE | CVE-2020-9320 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-20 22:15:00 UTC |
| Updated | 2023-11-07 03:26:00 UTC |
| Description | ** DISPUTED ** Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK. NOTE: Vendor asserts that vulnerability does not exist in product. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Avira | Anti-malware Sdk | All | All | All | All |
| Application | Avira | Anti-malware Sdk | All | All | All | All |
| Application | Avira | Antivirus Server | All | All | All | All |
| Application | Avira | Antivirus Server | All | All | All | All |
| Application | Avira | Avira Antivirus For Endpoint | All | All | All | All |
| Application | Avira | Avira Antivirus For Endpoint | All | All | All | All |
| Application | Avira | Avira Antivirus For Small Business | All | All | All | All |
| Application | Avira | Avira Antivirus For Small Business | All | All | All | All |
| Application | Avira | Avira Exchange Security | All | All | All | All |
| Application | Avira | Avira Exchange Security | All | All | All | All |
| Application | Avira | Avira Free Security Suite | All | All | All | All |
| Application | Avira | Avira Free Security Suite | All | All | All | All |
| Application | Avira | Avira Internet Security Suite | All | All | All | All |
| Application | Avira | Avira Internet Security Suite | All | All | All | All |
| Application | Avira | Avira Prime | All | All | All | All |
| Application | Avira | Avira Prime | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.zoller.lu/%5BTZO-01-2020%5D%20AVIRA%20Generic%20Bypass%20ISO.pdf | www.zoller.lu | ||
| AVIRA Generic Malformed Container Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Musings on Information Security and Data Privacy: [TZO-19-2020] - AVIRA Generic AV Bypass (ISO Container) | MISC | blog.zoller.lu | Third Party Advisory |
| www.zoller.lu/[TZO-01-2020]%20AVIRA%20Generic%20Bypass%20ISO.pdf | MISC | www.zoller.lu | Third Party Advisory |
| Full Disclosure: [TZO-19-2020] - AVIRA Generic AV Bypass (ISO Container) - CVE-2020-9320 | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.