CVE Published: 09/04/2024 |
CVE Updated: 12/08/2024 |
CVE Year: 2024 Source: Bitdefender |
Vendor: Bitdefender |
Product: GravityZone Control Center (On Premises) Status : PUBLISHED
CVE-2024-2223 Description
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
Metrics
CVSS Version: 3.1 |
Base Score: 8.1 HIGH Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H