CVE-2019-17102

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/01/2020
Last modified:
03/02/2020

Description

An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This issue affects: Bitdefender Bitdefender BOX 2 versions prior to 2.1.47.36.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bitdefender:box_2_firmware:*:*:*:*:*:*:*:* 2.1.47.36 (excluding)
cpe:2.3:h:bitdefender:box_2:-:*:*:*:*:*:*:*