Vulnerabilities > CVE-2020-15297 - Server-Side Request Forgery (SSRF) vulnerability in Bitdefender Update Server 3.4.0.276

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
bitdefender
CWE-918
critical

Summary

Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.

Vulnerable Configurations

Part Description Count
Application
Bitdefender
2

Common Weakness Enumeration (CWE)