Back

MEDIUM

Server Side Request Forgery in GravityZone Update Server Using Null Bytes (VA-12646)

Published Apr 4, 2025

Description

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing null-byte (%00) sequences. By crafting a request to a domain such as evil.com%00.bitdefender.com, an attacker can bypass the allowlist check, causing the proxy to forward requests to arbitrary external or internal systems.

Affected products

Remediation

Vendor solution

An automatic update to version 3.5.2.689 fixes the issue.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Bitdefender
Published Apr 4, 2025
Updated Apr 4, 2025
Reserved Mar 12, 2025
CISA Vulnrichment
Updated Apr 4, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a