9.8
CVE-2024-2224
- EPSS 0.65%
- Veröffentlicht 09.04.2024 13:15:33
- Zuletzt bearbeitet 07.02.2025 18:53:18
- Quelle cve-requests@bitdefender.com
- Teams Watchlist Login
- Unerledigt Login
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitdefender ≫ Endpoint Security Version7.0.5.200089 SwPlatformlinux
Bitdefender ≫ Endpoint Security Version7.9.9.380 SwPlatformwindows
Bitdefender ≫ Gravityzone Control Center Version6.36.1 SwEditionon_premises
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.65% | 0.698 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
cve-requests@bitdefender.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.