7.5
CVSSv2

CVE-2021-3554

Published: 24/11/2021 Updated: 25/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an malicious user to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions before 6.6.27.390; versions before 7.1.2.33. Bitdefender Unified Endpoint versions before 6.2.21.160. Bitdefender GravityZone versions before 6.24.1-1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bitdefender endpoint security tools

bitdefender gravityzone

bitdefender gravityzone 6.24.1-1