CVE-2019-12612: High severity bitdefender box vulnerability
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12612?
CVE-2019-12612 is a vulnerability in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API.
How does the vulnerability in Bitdefender BOX firmware work?
The vulnerability allows an attacker with presence in the Bitdefender BOX setup network to pass arbitrary code to the BOX appliance through the web API.
What is the severity of CVE-2019-12612?
The severity of CVE-2019-12612 is high with a CVSS severity score of 7.8.
Which versions of Bitdefender BOX firmware are affected by CVE-2019-12612?
Bitdefender BOX firmware versions before 2.1.37.37-34 are affected by CVE-2019-12612.
How can I fix the vulnerability in Bitdefender BOX firmware?
To fix the vulnerability, it is recommended to update Bitdefender BOX firmware to version 2.1.37.37-34 or later.