Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg6r-fv2h-h7xm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.

EPSS

Процентиль: 73%
0.00778
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-20
CWE-494

Связанные уязвимости

CVSS3: 6.4
nvd
больше 4 лет назад

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.

EPSS

Процентиль: 73%
0.00778
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-20
CWE-494