CVE-2023-6154
Last modified
CVE-2023-6154 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total Security: 27.0.25.114; Internet Security: 27.0.25.114; Antivirus Plus: 27.0.25.114; Antivirus Free: 27.0.25.114.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total Security: 27.0.25.114; Internet Security: 27.0.25.114; Antivirus Plus: 27.0.25.114; Antivirus Free: 27.0.25.114.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Antivirus | 27.0.25.114 |
| Bitdefender | Antivirus Plus | 27.0.25.114 |
| Bitdefender | Internet Security | 27.0.25.114 |
| Bitdefender | Total Security | 27.0.25.114 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-6154?
How severe is CVE-2023-6154?
How do I fix CVE-2023-6154?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-6148Qualys Jenkins Plugin for Policy Compliance prior to version…5.4
- CVE-2023-6149 Qualys Jenkins Plugin for WAS prior to version and includin…6.5
- CVE-2023-6150Incorrect Use of Privileged APIs vulnerability in ESKOM Comp…7.5
- CVE-2023-6151Incorrect Use of Privileged APIs vulnerability in ESKOM Comp…7.5
- CVE-2023-6152A user changing their email after signing up and verifying i…5.4
- CVE-2023-6153Authentication Bypass by Primary Weakness vulnerability in T…9.8
- CVE-2023-6155The Quiz Maker WordPress plugin before 6.4.9.5 does not adeq…5.3
- CVE-2023-6156Improper neutralization of livestatus command delimiters in …8.8
- CVE-2023-6157Improper neutralization of livestatus command delimiters in …8.8
- CVE-2023-6158The EventON - WordPress Virtual Event Calendar Plugin plugin…6.5
- CVE-2023-6159An issue has been discovered in GitLab CE/EE affecting all v…6.5
- CVE-2023-6160The LifterLMS – WordPress LMS Plugin for eLearning plugin fo…6.7
Are you affected by CVE-2023-6154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
