CVE-2021-3823

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/10/2021
Last modified:
03/11/2021

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior to 3.3.8.249.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:* 3.3.8.249 (excluding)