Vulnerability Description
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-2 that are running only on premise.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Gravityzone | < 6.38.1-2 |
Related Weaknesses (CWE)
References
- https://bitdefender.com/consumer/support/support/security-advisories/host-whitelBroken Link
- https://www.cve.org/CVERecord?id=CVE-2024-4177Third Party Advisory
- https://bitdefender.com/consumer/support/support/security-advisories/host-whitelBroken Link
FAQ
What is CVE-2024-4177?
CVE-2024-4177 is a vulnerability with a CVSS score of 8.1 (HIGH). A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console v...
How severe is CVE-2024-4177?
CVE-2024-4177 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4177?
Check the references section above for vendor advisories and patch information. Affected products include: Bitdefender Gravityzone.