CVE-2024-13871: Unauthenticated Command Injection in Bitdefender BOX v1
A command injection vulnerability exists in the /checkimageandtriggerrecovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13871?
CVE-2024-13871 is classified as a critical severity vulnerability due to its potential to allow unauthorized command execution.
What systems are affected by CVE-2024-13871?
CVE-2024-13871 affects the Bitdefender Box 1 running firmware version 1.3.11.490.
How do I fix CVE-2024-13871?
To address CVE-2024-13871, update the Bitdefender Box 1 to the latest firmware version provided by Bitdefender.
Can CVE-2024-13871 be exploited remotely?
Yes, CVE-2024-13871 can be exploited by unauthenticated, network-adjacent attackers.
What types of attacks can CVE-2024-13871 enable?
CVE-2024-13871 can enable arbitrary command execution on the affected device, potentially leading to a full system compromise.