PT-2024-5076 · Bitdefender · Gravityzone Console

N1Nj4Sec

+1

·

Published

2024-06-06

·

Updated

2024-06-11

·

CVE-2024-4177

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GravityZone Console versions prior to 6.38.1-2
Description: A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue is related to insufficient checking of incoming requests, which can be exploited by a remote attacker to perform an SSRF attack.
Recommendations: For GravityZone Console versions prior to 6.38.1-2, update to version 6.38.1-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy service to minimize the risk of exploitation.

Fix

Improper Encoding or Escaping of Output

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05603
CVE-2024-4177

Affected Products

Gravityzone Console