First published: Thu Oct 28 2021(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior to 3.3.8.249.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender GravityZone | <3.3.8.249 |
An automatic update to Bitdefender GravityZone Update Server to version 3.3.8.249 fixes the issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3823 is an Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in the UpdateServer component of Bitdefender GravityZone.
CVE-2021-3823 has a severity rating of 9.8 (Critical).
Bitdefender GravityZone versions prior to 3.3.8.249 are affected by CVE-2021-3823.
An attacker can exploit CVE-2021-3823 by executing arbitrary code on vulnerable instances of Bitdefender GravityZone.
To fix CVE-2021-3823, update Bitdefender GravityZone to version 3.3.8.249 or later.