CVE-2024-4177: Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-2 that are running only on premise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GravityZone Console On-Premiseto a version that resolves this vulnerability.Fixed in 6.38.1-2Patch VA-11554
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4177?
CVE-2024-4177 is considered a high severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2024-4177?
To fix CVE-2024-4177, upgrade your Bitdefender GravityZone Console to version 6.38.1-2 or later.
Which versions of GravityZone are affected by CVE-2024-4177?
CVE-2024-4177 affects all versions of GravityZone Console before 6.38.1-2 that are running on-premise.
What type of vulnerability is CVE-2024-4177?
CVE-2024-4177 is a host whitelist parser issue that allows for server-side request forgery.
Is CVE-2024-4177 remote or local?
CVE-2024-4177 can be exploited remotely since it involves a server-side request forgery vulnerability.