Vulnerabilities > CVE-2021-3485 - Unspecified vulnerability in Bitdefender Endpoint Security Tools 6.2.21.18
Attack vector
NETWORK Attack complexity
HIGH Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://herolab.usd.de/security-advisories/usd-2021-0014/
- https://herolab.usd.de/security-advisories/usd-2021-0014/
- https://www.bitdefender.com/support/security-advisories/improper-input-validation-in-bitdefender-endpoint-security-tools-for-linux-va-9769
- https://www.bitdefender.com/support/security-advisories/improper-input-validation-in-bitdefender-endpoint-security-tools-for-linux-va-9769