CVE-2021-3553: Server-Side Request Forgery in EPPUpdateService remote config file (VA-9825)
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint for Linux versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-3553?
CVE-2021-3553 is a Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools.
How does the SSRF vulnerability in Bitdefender Endpoint Security Tools work?
The SSRF vulnerability allows an attacker to use the Endpoint Protection relay as a proxy for any remote host.
Which versions of Bitdefender Endpoint Security Tools are affected by CVE-2021-3553?
Bitdefender Endpoint Security Tools versions prior to 6.6.27.390 are affected.
What is the severity of CVE-2021-3553?
The severity of CVE-2021-3553 is high with a CVSS score of 7.5.
How can I fix CVE-2021-3553?
To fix CVE-2021-3553, update Bitdefender Endpoint Security Tools to version 6.6.27.390 or later.