Back

CRITICAL

Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)

Published Sep 5, 2022

Description

Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.

Affected products

Remediation

Vendor solution

An automatic update to the following software versions fixes the issue:

Bitdefender GravityZone Console On-Premise version 6.29.2-1. Bitdefender GravityZone Cloud Console version 6.27.2-2.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Bitdefender
Published Sep 5, 2022
Updated Sep 16, 2024
Reserved Aug 16, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a