Improper Access Control in Bitdefender Box by Bitdefender
CVE-2024-13870
1.8LOW
What is CVE-2024-13870?
An improper access control vulnerability present in Bitdefender Box 1 allows unauthorized users to perform firmware downgrades. This flaw permits an attacker within WiFi range to exploit the device when booted in Recovery Mode, thereby reverting to an older firmware version that might harbor known vulnerabilities. This manipulation can significantly compromise the security of the device and the network it protects.
Affected Version(s)
BOX v1 0 <= 1.3.52.928
References
CVSS V4
Score:
1.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bitdefender Labs
