CVE-2024-2223: Incorrect Regular Expression in GravityZone Update Server (VA-11465)
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2223?
The severity of CVE-2024-2223 is classified as high due to its potential for server-side request forgery.
How do I fix CVE-2024-2223?
To mitigate CVE-2024-2223, ensure your Bitdefender products are updated to the latest version that addresses this vulnerability.
Which products are affected by CVE-2024-2223?
CVE-2024-2223 affects Bitdefender Endpoint Security for Linux, Bitdefender Endpoint Security for Windows, and Bitdefender GravityZone Control Center.
What type of attack can CVE-2024-2223 facilitate?
CVE-2024-2223 can facilitate a server-side request forgery attack, allowing an attacker to manipulate requests sent by the server.
What is the cause of CVE-2024-2223?
CVE-2024-2223 is caused by an incorrect regular expression vulnerability present in the Bitdefender GravityZone Update Server.