MEDIUM🇵🇱 Wersja polska

CVE-2019-12611

CVSS 4.4v3.1pub. 2019-10-17upd. 2024-11-21

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
  • Bitdefender Box

    HW
    Bitdefender
    all versions
  • Bitdefender Box Firmware

    OS
    Bitdefender
    < 2.1.37.37-34
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-13871CRITICAL9.4PL ✓same product

Command injection w Bitdefender Box 1 — nieuwierzytelniony RCE

CVE-2024-13872CRITICAL9.4PL ✓same product

Niezabezpieczony mechanizm aktualizacji w Bitdefender Box — RCE przez MITM

CVE-2019-12612HIGH7.8same product

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pa...

CVE-2024-13870LOW1.8same product

W Bitdefender Box 1 (wersja oprogramowania 1.3.52.928 i starsze) istnieje podatność w kontroli dostępu, która ...

CVE-2025-1987CRITICAL9.3PL ✓same vendor

Stored XSS w Psono Client / Bitdefender SecurePass via złośliwe URL w magazynie haseł