Improper Access Control vulnerability in the patchesUpdate API
Vulnerability Description
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3554
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Nicolas VERDIER, Cybersecurity Consultant at TEHTRIS
More from Bitdefender
View All →Affected Vendor
Bitdefender
View all reports →