Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g45m-r7f4-g5c2

Опубликовано: 12 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 7.5

Описание

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

EPSS

Процентиль: 19%
0.00061
Низкий

9.4 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

CVSS3: 9.6
fstec
11 месяцев назад

Уязвимость реализации протокола HTTP устройства для защиты приборов и гаджетов Bitdefender BOX 1, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 19%
0.00061
Низкий

9.4 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-319