CVE-2021-3960

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior to 3.3.8.272
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:*

History

21 Dec 2021, 17:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
References (MISC) https://www.bitdefender.com/support/security-advisories/privilege-escalation-via-the-gravityzone-productmanager-updateserver-kitsmanager-api-va-10146 - (MISC) https://www.bitdefender.com/support/security-advisories/privilege-escalation-via-the-gravityzone-productmanager-updateserver-kitsmanager-api-va-10146 - Vendor Advisory
CWE CWE-22
CPE cpe:2.3:a:bitdefender:gravityzone:*:*:*:*:*:*:*:*

16 Dec 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-16 15:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-3960

Mitre link : CVE-2021-3960

CVE.ORG link : CVE-2021-3960


JSON object : View

Products Affected

bitdefender

  • gravityzone
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')