Insecure Update Mechanism in Bitdefender Box Affects Device Security
CVE-2024-13872
What is CVE-2024-13872?
The Bitdefender Box has a vulnerability that results from using the insecure HTTP protocol for downloading essential assets for updates and daemon restarts. This flaw allows remote attackers to exploit the API method /set_temp_token to execute man-in-the-middle (MITM) attacks. By intercepting these updates, attackers can inject malicious responses, which could lead to remote code execution through compromised daemons using affected updates. This vulnerability poses a significant risk to the security and integrity of the affected devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BOX v1 1.3.11.490 < 1.3.11.505
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
