CVE-2019-17096: Bitdefender BOX 2 bootstrap get_image_size command injection vulnerability
A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the getimageurl() function in special circumstances to inject a system command.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-17096?
CVE-2019-17096 is an OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2.
How does CVE-2019-17096 affect Bitdefender BOX 2?
CVE-2019-17096 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.
What is the severity of CVE-2019-17096?
CVE-2019-17096 has a severity rating of 9.8 (Critical).
How can I fix CVE-2019-17096?
To fix CVE-2019-17096, update to the latest version of Bitdefender BOX 2 firmware.
Where can I find more information about CVE-2019-17096?
You can find more information about CVE-2019-17096 at the following link: [https://www.bitdefender.com/support/security-advisories/bitdefender-box-2-bootstrap-get_image_size-command-injection-vulnerability/](https://www.bitdefender.com/support/security-advisories/bitdefender-box-2-bootstrap-get_image_size-command-injection-vulnerability/)