CVE-2021-3959: Server-Side Request Forgery in Bitdefender GravityZone Update Server in Relay Mode (VA-10145)
Published Dec 16, 2021
·Updated
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272
Affected Software
1 affected component
Bitdefender GravityZone<3.3.8.272
Remediation
Information
An automatic update to version 3.3.8.272 fixes the issue.
Event History
Dec 16, 2021
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2021-3959.
2
What is the severity of CVE-2021-3959?
The severity of CVE-2021-3959 is high with a CVSS score of 7.5.
3
Which component of Bitdefender Endpoint Security Tools is affected by CVE-2021-3959?
The EPPUpdateService component of Bitdefender Endpoint Security Tools is affected by CVE-2021-3959.
4
What is the impact of CVE-2021-3959?
CVE-2021-3959 allows an attacker to proxy requests to the relay server, leading to potential data leakage or unauthorized access.
5
How can I mitigate CVE-2021-3959?
Update Bitdefender GravityZone to version 3.3.8.272 or higher to mitigate CVE-2021-3959.