HIGH
Bitdefender BOX v2 bootstrap update_setup command execution vulnerability (VA-2226)
Published Jan 27, 2020
8.3
HIGHCVSS 3.1
EPSS 1.95%
Description
An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This issue affects: Bitdefender Bitdefender BOX 2 versions prior to 2.1.47.36.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<2.1.47.36
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bitdefender | Bitdefender BOX 2 | n/a |
|
AND
- < 2.1.47.36
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Updating to firmware version 2.1.47.36 resolves this issue.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7568 Advisory
- https://www.bitdefender.com/support/security-advisories/bitdefender-box-v2-bootstrap-update_setup-command-execution-vulnerability-va-2226 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7568 | Advisory | |
| https://www.bitdefender.com/support/security-advisories/bitdefender-box-v2-bootstrap-update_setup-command-execution-vulnerability-va-2226 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Bitdefender
Published Jan 27, 2020
Updated Sep 17, 2024
Reserved Oct 2, 2019
Link CVE-2019-17102
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-7568 Assigner Bitdefender
Published Jan 27, 2020
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2019-7568