CVE-2021-3485
Published on: 05/24/2021 12:00:00 AM UTC
Last Modified on: 02/16/2023 02:47:00 AM UTC
Certain versions of Endpoint Security Tools from Bitdefender contain the following vulnerability:
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.
- CVE-2021-3485 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Bitdefender - Endpoint Security Tools for Linux version = unspecified
CVSS3 Score: 6.6 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Improper Input Validation in Bitdefender Endpoint Security Tools for Linux (VA-9769) - Bitdefender | www.bitdefender.com text/html |
![]() |
usd-2021-0014 | usd Herolab | herolab.usd.de text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Bitdefender | Endpoint Security Tools | All | All | All | All |
- cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:linux:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-3485 : An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Se… twitter.com/i/web/status/1… | 2021-05-24 13:33:31 |
![]() |
CVE-2021-3485 | 2021-05-24 13:41:26 |