First published: Wed Mar 12 2025(Updated: )
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender Box | <1.3.52.928 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13870 is considered a high severity vulnerability due to the potential for unauthorized firmware downgrades.
To fix CVE-2024-13870, update your Bitdefender Box firmware to version 1.3.52.929 or later.
CVE-2024-13870 affects Bitdefender Box devices with firmware version 1.3.52.928 and below.
CVE-2024-13870 enables an unauthenticated attacker to downgrade the device's firmware to a potentially vulnerable version.
No, CVE-2024-13870 can be exploited without user authentication.