Insufficient validation on regular expression in EPPUpdateService config file (VA-9825)
Vulnerability Description
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone 6.24.1-1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3552
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Nicolas VERDIER, Cybersecurity Consultant at TEHTRIS
More from Bitdefender
View All →Affected Vendor
Bitdefender
View all reports →