CVE-2021-3554

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/11/2021
Last modified:
25/04/2022

Description

Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:*:*:* 6.6.27.390 (excluding)
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:linux:*:* 6.6.27.390 (excluding)
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:*:*:* 7.0.0.00 (including) 7.1.2.33 (excluding)
cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:* 6.24.1-1 (excluding)
cpe:2.3:a:bitdefender:gravityzone:6.24.1-1:*:*:*:*:*:*:*