← Back

CVE-2021-3553

nvd nist
Published: Nov 24, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint for Linux versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.

Affected (4)

2 products
Endpoint Security Tools
Gravityzone
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Bitdefender
From 6.6.27.0 to 6.6.27.390
From 7.0.0.00 to 7.1.2.33
Before 6.2.21.160
Version 6.24.1-1

Timeline

No history available yet.