Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.
2021-11-24T16:15:13.797
2024-11-21T06:21:49.727
Modified
CVSSv3.1: 9.0 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bitdefender | endpoint_security_tools | < 6.6.27.390 | Yes |
Application | bitdefender | endpoint_security_tools | < 6.6.27.390 | Yes |
Application | bitdefender | endpoint_security_tools | < 7.1.2.33 | Yes |
Application | bitdefender | gravityzone | < 6.24.1-1 | Yes |
Application | bitdefender | gravityzone | 6.24.1-1 | Yes |