CVE-2021-3552: Insufficient validation on regular expression in EPPUpdateService config file (VA-9825)
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone 6.24.1-1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3552?
CVE-2021-3552 is a Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools.
How does CVE-2021-3552 affect Bitdefender Endpoint Security Tools?
CVE-2021-3552 affects Bitdefender Endpoint Security Tools versions prior to 6.6.27.390 and versions prior to 7.1.2.33.
How can an attacker exploit CVE-2021-3552?
An attacker can exploit CVE-2021-3552 by proxying requests to the relay server.
What is the severity of CVE-2021-3552?
CVE-2021-3552 has a severity rating of 7.5 (high).
How can I fix CVE-2021-3552?
To fix CVE-2021-3552, update Bitdefender Endpoint Security Tools to version 6.6.27.390 or higher for versions prior to 7.1.2.33, and to version 7.1.2.33 or higher for versions prior to 6.2.21.160.