Skip to main content

CVE-2024-2223

8.1
HIGHCVSS v3.1 Base Score
0.50%
LOW RiskEPSS (66th percentile)

An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:  Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for  Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1

Published: 4/9/2024
Modified: 2/7/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.50%LOW Exploitation Risk
66th percentile

This vulnerability has a 0.50% probability of being exploited in the next 30 days, ranking higher than 66% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-185)

Similar SeverityHIGH