VYPR

Gravityzone Update Server

by Bitdefender

CVEs (4)

  • CVE-2024-6980CriJul 31, 2024
    risk 0.64cvss 9.8epss 0.01

    A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.

  • CVE-2024-2223HigApr 9, 2024
    risk 0.53cvss 8.1epss 0.01

    An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:  Bitdefender Endpoint…

  • CVE-2021-3823HigOct 28, 2021
    risk 0.46cvss 7.1epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior…

  • CVE-2025-2245MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.00

    A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing…