CVE-2021-3823: Path traversal vulnerability in Bitdefender GravitZone Update Server in relay mode
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior to 3.3.8.249.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-3823?
CVE-2021-3823 is an Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in the UpdateServer component of Bitdefender GravityZone.
How severe is CVE-2021-3823?
CVE-2021-3823 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-3823?
Bitdefender GravityZone versions prior to 3.3.8.249 are affected by CVE-2021-3823.
How can an attacker exploit CVE-2021-3823?
An attacker can exploit CVE-2021-3823 by executing arbitrary code on vulnerable instances of Bitdefender GravityZone.
How can I fix CVE-2021-3823?
To fix CVE-2021-3823, update Bitdefender GravityZone to version 3.3.8.249 or later.