First published: Mon Nov 09 2020(Updated: )
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
BitDefender Update Server | <6.6.20.294 |
Version 6.6.20.294 of the Bitdefender Update Server fixes the issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15297 is a vulnerability in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools.
CVE-2020-15297 has a severity rating of 9.1 (critical).
Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 are affected by CVE-2020-15297.
CVE-2020-15297 allows an unprivileged attacker to bypass mitigations and interact with hosts on the network.
Yes, updating to Bitdefender Endpoint Security Tools version 6.6.20.294 or later fixes CVE-2020-15297.