Bitdefender BOX 2 bootstrap get_image_size command injection vulnerability
CVE-2019-17096

9CRITICAL

Key Information:

Vendor
CVE Published:
27 January 2020

What is CVE-2019-17096?

A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the get_image_url() function in special circumstances to inject a system command.

Affected Version(s)

Bitdefender BOX 2 2.1.47.42 < 2.1.59-12

Bitdefender BOX 2 2.1.53.45 < 2.1.59-12

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claudio Bozzato, Lilith Wyatt and Dave McDaniel of Cisco Talos.
.