CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-13872

CVSS 9.4v4.0pub. 2025-03-12upd. 2025-07-30

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.

🤖 AI Analysis
How it works

The Bitdefender Box initiates downloading of update assets and detection rules through an unencrypted HTTP protocol. The update process can be remotely triggered using the /set_temp_token API method. An attacker located in the network vicinity can use MITM techniques to intercept the HTTP connection and substitute malicious assets in place of legitimate ones. After daemons restart and load the substituted assets, the attacker gains the ability to execute arbitrary code on the device.

Impact

An unauthenticated attacker with network access can obtain remote code execution (RCE) on the Bitdefender Box device, leading to complete takeover of the device and potential breach of confidentiality, integrity, and availability of both the device itself and the network it protects.

Mitigation & patch

Update the Bitdefender Box device firmware to a version higher than 1.3.11.505, applying patches available from the manufacturer in accordance with references published in the Bitdefender security bulletin.

Who is affected

Bitdefender Box (firmware) in versions 1.3.11.490 to 1.3.11.505 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bitdefender Box

    HW
    Bitdefender
    all versions
  • Bitdefender Box Firmware

    OS
    Bitdefender
    1.3.11.490 – 1.3.11.505
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-13871CRITICAL9.4PL ✓same product

Command injection w Bitdefender Box 1 — nieuwierzytelniony RCE

CVE-2019-12612HIGH7.8same product

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pa...

CVE-2019-12611MEDIUM4.4same product

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reli...

CVE-2024-13870LOW1.8same product

W Bitdefender Box 1 (wersja oprogramowania 1.3.52.928 i starsze) istnieje podatność w kontroli dostępu, która ...

CVE-2025-1987CRITICAL9.3PL ✓same vendor

Stored XSS w Psono Client / Bitdefender SecurePass via złośliwe URL w magazynie haseł