A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.
2020-01-27T17:15:12.073
2024-11-21T04:31:41.107
Modified
CVSSv3.1: 9.0 (CRITICAL)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | bitdefender | box_2_firmware | - | Yes |
Hardware | bitdefender | box_2 | - | No |
Application | bitdefender | central | < 2.0.66 | Yes |
Application | bitdefender | central | < 2.0.66.88 | Yes |