Vulnerability Description
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Update Server | < 6.6.20.294 |
Related Weaknesses (CWE)
References
- https://www.bitdefender.com/support/security-advisories/server-side-request-forgVendor Advisory
- https://www.bitdefender.com/support/security-advisories/server-side-request-forgVendor Advisory
FAQ
What is CVE-2020-15297?
CVE-2020-15297 is a vulnerability with a CVSS score of 7.1 (HIGH). Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-...
How severe is CVE-2020-15297?
CVE-2020-15297 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15297?
Check the references section above for vendor advisories and patch information. Affected products include: Bitdefender Update Server.