Improper Access Control vulnerability in the patchesUpdate API
Published Nov 24, 2021
10.0
CRITICALCVSS 3.1
EPSS 2.12%
Description
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.
Affected products
-
Affected
- ≥ unspecified, < 6.6.27.390
- ≥ unspecified, < 7.1.2.33
-
Affected
- ≥ unspecified, < 6.24.1-1
-
Affected
- ≥ unspecified, < 6.2.21.160
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Bitdefender | Endpoint Security Tools for Linux | unknown | Affected
|
| Bitdefender | GravityZone | unknown | Affected
|
| Bitdefender | Unified Endpoint | unknown | Affected
|
- < 6.6.27.390
- < 6.6.27.390
- ≥ 7.0.0.00 · < 7.1.2.33
- < 6.24.1-1
- 6.24.1-1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
An automatic update to version 6.6.27.390 fixes the issue.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26865 Advisory
- https://www.bitdefender.com/support/security-advisories/improper-access-control-vulnerability-patchesupdate-api-va-9825 x_refsource_MISCBroken Link
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26865 | Advisory | |
| https://www.bitdefender.com/support/security-advisories/improper-access-control-vulnerability-patchesupdate-api-va-9825 | x_refsource_MISCBroken Link |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data