CVE-2020-8987 describes a critical vulnerability in Avast AntiTrack (before 1.5.1.172) and AVG AntiTrack (before 2.0.0.178) where the software, in its default configuration, proxies HTTPS traffic without validating certificates. This flaw allows a man-in-the-middle attacker to intercept and potentially manipulate encrypted communications using a self-signed certificate, requiring no user interaction. Rated 7.4 HIGH on CVSS, the vulnerability has a network attack vector and high impact on confidentiality and integrity. While no active exploitation or public exploit code has been identified, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1.172CPE matchmatch criteria | cpe:2.3:a:avast:antitrack:*:*:*:*:*:*:*:* | ||
< 2.0.0.178CPE matchmatch criteria | cpe:2.3:a:avast:avg_antitrack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.