First published: Thu Oct 31 2019(Updated: )
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender BOX firmware | <2.1.37.37-34 | |
Bitdefender BOX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12612 is a vulnerability in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API.
The vulnerability allows an attacker with presence in the Bitdefender BOX setup network to pass arbitrary code to the BOX appliance through the web API.
The severity of CVE-2019-12612 is high with a CVSS severity score of 7.8.
Bitdefender BOX firmware versions before 2.1.37.37-34 are affected by CVE-2019-12612.
To fix the vulnerability, it is recommended to update Bitdefender BOX firmware to version 2.1.37.37-34 or later.