// For flags

CVE-2022-0677

Improper Handling of Length Parameter Inconsistency vulnerability in Bitdefender Update Server (VA-10144)

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.

Una vulnerabilidad de Manejo Inapropiado de la Inconsistencia de los Parámetros de Longitud en el componente Update Server de Bitdefender Endpoint Security Tools (en el rol relay), GravityZone (en el rol Update Server) permite a un atacante causar una Denegación de Servicio. Este problema afecta a: Bitdefender Update Server versiones anteriores a 3.4.0.276. Bitdefender Update Server versiones anteriores a la 26.4-1. Bitdefender Endpoint Security Tools for Linux versiones anteriores a 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versiones anteriores a 7.4.1.111

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-18 CVE Reserved
  • 2022-04-07 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-11-11 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-130: Improper Handling of Length Parameter Inconsistency
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bitdefender
Search vendor "Bitdefender"
Endpoint Security Tools
Search vendor "Bitdefender" for product "Endpoint Security Tools"
< 6.2.21.171
Search vendor "Bitdefender" for product "Endpoint Security Tools" and version " < 6.2.21.171"
linux
Affected
Bitdefender
Search vendor "Bitdefender"
Endpoint Security Tools
Search vendor "Bitdefender" for product "Endpoint Security Tools"
< 7.4.1.111
Search vendor "Bitdefender" for product "Endpoint Security Tools" and version " < 7.4.1.111"
windows
Affected
Bitdefender
Search vendor "Bitdefender"
Gravityzone
Search vendor "Bitdefender" for product "Gravityzone"
< 26.4-1
Search vendor "Bitdefender" for product "Gravityzone" and version " < 26.4-1"
-
Affected
Bitdefender
Search vendor "Bitdefender"
Update Server
Search vendor "Bitdefender" for product "Update Server"
< 3.4.0.276
Search vendor "Bitdefender" for product "Update Server" and version " < 3.4.0.276"
-
Affected