PT-2025-14875 · Bitdefender · Bitdefender Gravityzone Update Server
Nicolas Verdier
·
Published
2025-04-04
·
Updated
2025-08-21
·
CVE-2025-2245
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Bitdefender GravityZone Update Server (affected versions not specified)
Description
A server-side request forgery (SSRF) issue exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests but fails to properly sanitize hostnames containing null-byte (%00) sequences. By manipulating a request to a domain such as
evil.com%00.bitdefender.com, an attacker can bypass the allowlist check, causing the proxy to forward requests to arbitrary external or internal systems.Recommendations
As a temporary workaround, consider restricting access to the HTTP proxy component on port 7074 to minimize the risk of exploitation.
Avoid using the proxy in Relay Mode until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitdefender Gravityzone Update Server