Логотип exploitDog
bind:CVE-2024-13872
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-13872

Количество 3

Количество 3

nvd логотип

CVE-2024-13872

11 месяцев назад

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g45m-r7f4-g5c2

11 месяцев назад

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-03184

11 месяцев назад

Уязвимость реализации протокола HTTP устройства для защиты приборов и гаджетов Bitdefender BOX 1, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-13872

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-g45m-r7f4-g5c2

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03184

Уязвимость реализации протокола HTTP устройства для защиты приборов и гаджетов Bitdefender BOX 1, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 9.6
0%
Низкий
11 месяцев назад

Уязвимостей на страницу