CVE-2020-15297: SSRF
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-15297?
CVE-2020-15297 is a vulnerability in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools.
How severe is CVE-2020-15297?
CVE-2020-15297 has a severity rating of 9.1 (critical).
Which version of Bitdefender Endpoint Security Tools is affected by CVE-2020-15297?
Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 are affected by CVE-2020-15297.
What is the impact of CVE-2020-15297?
CVE-2020-15297 allows an unprivileged attacker to bypass mitigations and interact with hosts on the network.
Is there a fix for CVE-2020-15297?
Yes, updating to Bitdefender Endpoint Security Tools version 6.6.20.294 or later fixes CVE-2020-15297.