CVE-2019-17095
A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the condition, an unauthenticated attacker should impersonate a infrastructure server to trigger this vulnerability.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.23% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- bitdefender/box 2 firmware
- Source
- cve-requests@bitdefender.com
References
- https://www.bitdefender.com/support/security-advisories/command-injection-vulnerability-in-bitdefender-box-v2-va-5706Broken Link
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0919Exploit, Third Party Advisory
- https://www.cybersecurity-help.cz/vdb/SB2020012215?affChecked=1Third Party Advisory
- https://www.bitdefender.com/support/security-advisories/command-injection-vulnerability-in-bitdefender-box-v2-va-5706Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.