CVE-2021-3959

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
16/12/2021
Last modified:
22/12/2021

Description

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:* 3.3.8.272 (excluding)