Session Management Issue in Avast Antivirus Password Manager
CVE-2020-15024

5.5MEDIUM

Key Information:

Vendor

Avast

Status
Vendor
CVE Published:
10 September 2020

What is CVE-2020-15024?

A flaw in the Password Manager component of Avast Antivirus allows sensitive data to remain in memory even after users log out or lock the vault. This vulnerability can lead to potential information disclosure, as the stored passwords may be accessible to unauthorized users if they gain access to the system's memory.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.