CVE Vulnerabilities

CVE-2021-3554

Published: Nov 24, 2021 | Modified: Apr 25, 2022
CVSS 3.x
10
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.

Affected Software

Name Vendor Start Version End Version
Endpoint_security_tools Bitdefender * 6.6.27.390 (excluding)
Endpoint_security_tools Bitdefender 7.0.0.00 (including) 7.1.2.33 (excluding)
Gravityzone Bitdefender * 6.24.1-1 (excluding)
Gravityzone Bitdefender 6.24.1-1 (including) 6.24.1-1 (including)

References