An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: 

Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for  Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
Advisories
Source ID Title
EUVD EUVD EUVD-2024-27179 An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:  Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for  Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
Fixes

Solution

An automatic update to the following versions fixes the issues: Bitdefender Endpoint Security for Linux version 7.0.5.200090 Bitdefender Endpoint Security for Windows version 7.9.9.381 GravityZone Control Center (On Premises) version 6.36.1-1


Workaround

No workaround given by the vendor.

History

Fri, 07 Feb 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Bitdefender
Bitdefender endpoint Security
Bitdefender gravityzone Control Center
Weaknesses CWE-697
CPEs cpe:2.3:a:bitdefender:endpoint_security:7.0.5.200089:*:*:*:*:linux:*:*
cpe:2.3:a:bitdefender:endpoint_security:7.9.9.380:*:*:*:*:windows:*:*
cpe:2.3:a:bitdefender:gravityzone_control_center:6.36.1:*:*:*:on_premises:*:*:*
Vendors & Products Bitdefender
Bitdefender endpoint Security
Bitdefender gravityzone Control Center

cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2024-08-12T17:59:36.379Z

Reserved: 2024-03-06T14:44:01.368Z

Link: CVE-2024-2223

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:39.042Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T13:15:33.057

Modified: 2025-02-07T19:00:24.650

Link: CVE-2024-2223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.