Medium severity6.4NVD Advisory· Published May 24, 2021· Updated Jun 17, 2026
CVE-2021-3485
CVE-2021-3485
Description
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:linux:*:*Range: <6.2.21.155
<6.2.21.155+ 1 more
- (no CPE)range: <6.2.21.155
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- herolab.usd.de/security-advisories/usd-2021-0014/nvdExploitThird Party Advisory
- www.bitdefender.com/support/security-advisories/improper-input-validation-in-bitdefender-endpoint-security-tools-for-linux-va-9769nvdVendor Advisory
News mentions
0No linked articles in our index yet.