CVE-2024-2223
Incorrect Regular Expression in GravityZone Update Server (VA-11465)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
Una vulnerabilidad de expresión regular incorrecta en Bitdefender GravityZone Update Server permite a un atacante provocar Server Side Request Forgery y reconfigurar el relé. Este problema afecta a los siguientes productos que incluyen el componente vulnerable: Bitdefender Endpoint Security para Linux versión 7.0.5.200089 Bitdefender Endpoint Security para Windows versión 7.9.9.380 GravityZone Control Center (On Premises) versión 6.36.1
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-02-28 First Exploit
- 2024-03-06 CVE Reserved
- 2024-04-09 CVE Published
- 2024-04-10 EPSS Updated
- 2024-08-12 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-185: Incorrect Regular Expression
CAPEC
- CAPEC-664: Server Side Request Forgery
References (2)
URL | Tag | Source |
---|---|---|
https://www.bitdefender.com/support/security-advisories/incorrect-regular-expression-in-gravityzone-update-server-va-11465 |
URL | Date | SRC |
---|---|---|
https://github.com/shellfeel/CVE-2024-22243-CVE-2024-22234 | 2024-02-28 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bitdefender Search vendor "Bitdefender" | GravityZone Control Center (On Premises) Search vendor "Bitdefender" for product "GravityZone Control Center (On Premises)" | 6.36.1 Search vendor "Bitdefender" for product "GravityZone Control Center (On Premises)" and version "6.36.1" | en |
Affected
| ||||||
Bitdefender Search vendor "Bitdefender" | Endpoint Security For Windows Search vendor "Bitdefender" for product "Endpoint Security For Windows" | 7.9.9.380 Search vendor "Bitdefender" for product "Endpoint Security For Windows" and version "7.9.9.380" | en |
Affected
| ||||||
Bitdefender Search vendor "Bitdefender" | Endpoint Security For Linux Search vendor "Bitdefender" for product "Endpoint Security For Linux" | 7.0.5.200089 Search vendor "Bitdefender" for product "Endpoint Security For Linux" and version "7.0.5.200089" | en |
Affected
|