CVE-2021-3485
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/05/2021
Last modified:
16/09/2024
Description
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.
Impact
Base Score 3.x
6.60
Severity 3.x
MEDIUM
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:linux:*:* | 6.2.21.155 (excluding) |
To consult the complete list of CPE names with products and versions, see this page