Bitdefender BOX 2 bootstrap get_image_size command injection vulnerability
CVE-2019-17096
9CRITICAL
What is CVE-2019-17096?
A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the get_image_url()
function in special circumstances to inject a system command.
Affected Version(s)
Bitdefender BOX 2 2.1.47.42 < 2.1.59-12
Bitdefender BOX 2 2.1.53.45 < 2.1.59-12
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Claudio Bozzato, Lilith Wyatt and Dave McDaniel of Cisco Talos.