Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wpx-wqvh-rxw6

Опубликовано: 12 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1.8
CVSS3: 5.7

Описание

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.

EPSS

Процентиль: 11%
0.00038
Низкий

1.8 Low

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-1328

Связанные уязвимости

CVSS3: 5.7
nvd
11 месяцев назад

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.

EPSS

Процентиль: 11%
0.00038
Низкий

1.8 Low

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-1328