CVE-2014-5350: Path Traversal
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5350?
CVE-2014-5350 is classified as a critical vulnerability due to its potential for remote file access.
How do I fix CVE-2014-5350?
To mitigate CVE-2014-5350, update Bitdefender GravityZone to version 5.1.11.432 or later.
What types of attacks are possible with CVE-2014-5350?
CVE-2014-5350 allows remote attackers to perform directory traversal attacks to read arbitrary files on the server.
Which versions of Bitdefender GravityZone are vulnerable to CVE-2014-5350?
Bitdefender GravityZone versions prior to 5.1.11.432 are vulnerable to CVE-2014-5350.
Where can CVE-2014-5350 be exploited?
CVE-2014-5350 can be exploited through the Web Console interface of Bitdefender GravityZone.