CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-6980

CVSS 9.2v4.0pub. 2024-07-31upd. 2025-02-07

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.

🤖 AI Analysis
How it works

The proxy service in GravityZone Update Server exposes error information in excessive detail (CWE-209), enabling an attacker to manipulate server-side requests (CWE-918). Exploiting this vulnerability, an unauthenticated remote attacker can cause the server to execute HTTP requests to internal network resources. The attack is possible without user interaction, however it requires a certain level of complexity on the attacker's side (AC:H according to the CVSS vector).

Impact

An attacker can gain unauthorized access to internal network resources and services that are not directly accessible from outside, which may lead to disclosure of sensitive data or further compromise of system integrity and availability.

Mitigation & patch

Bitdefender GravityZone Console should be updated to version 6.38.1-5 or newer. Detailed information is available in the official Bitdefender security advisory at the address indicated in the references.

Who is affected

Bitdefender GravityZone Console in versions before 6.38.1-5, operating only in on-premise mode (local installations). Cloud installations are not vulnerable.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bitdefender Gravityzone

    APP
    Bitdefender
    < 6.38.1-5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2025-2244CRITICAL9.5PL ✓same product

Niebezpieczna deserializacja PHP w Bitdefender GravityZone Console (RCE)

CVE-2021-3554CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w API patchesUpdate — Bitdefender Endpoint Security Tools

CVE-2017-8931CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp z uprawnieniami root w Bitdefender GravityZone VMware

CVE-2018-8955CRITICAL9.8PL ✓same product

Bitdefender GravityZone – pominięcie weryfikacji podpisu i RCE przez instalator

CVE-2024-4177HIGH8.1same product

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an atta...