CVE-2019-17102: Bitdefender BOX v2 bootstrap update_setup command execution vulnerability (VA-2226)
An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method /api/updatesetup does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This issue affects: Bitdefender Bitdefender BOX 2 versions prior to 2.1.47.36.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17102?
The severity of CVE-2019-17102 is critical with a severity value of 8.1.
What is the affected software of CVE-2019-17102?
The affected software of CVE-2019-17102 is Bitdefender BOX 2 firmware version up to 2.1.47.36.
How can the vulnerability in CVE-2019-17102 be exploited?
The vulnerability in CVE-2019-17102 can be exploited by performing an arbitrary execution of system commands through a race condition in the API method /api/update_setup.
Is Bitdefender BOX 2 vulnerable to CVE-2019-17102?
No, Bitdefender BOX 2 is not vulnerable to CVE-2019-17102.
How can I fix the vulnerability in CVE-2019-17102?
To fix the vulnerability in CVE-2019-17102, users should apply the necessary firmware update provided by Bitdefender.