CVE-2019-17095

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
27/01/2020
Last modified:
01/02/2020

Description

A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the condition, an unauthenticated attacker should impersonate a infrastructure server to trigger this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bitdefender:box_2_firmware:2.1.47.42:*:*:*:*:*:*:*
cpe:2.3:o:bitdefender:box_2_firmware:2.1.53.45:*:*:*:*:*:*:*
cpe:2.3:h:bitdefender:box_2:-:*:*:*:*:*:*:*