Server-Side Request Forgery Vulnerability in GravityZone Console
CVE-2024-4177

9.8CRITICAL

Key Information:

Vendor
CVE Published:
6 June 2024

What is CVE-2024-4177?

The vulnerability involves a flaw in the host whitelist parser within the proxy service of the GravityZone Update Server, which can be exploited to carry out server-side request forgery (SSRF) attacks. This defect is present in all versions of the GravityZone Console running on-premise prior to 6.38.1-2. An attacker leveraging this issue can potentially manipulate server requests, posing harmful impacts on the underlying system and its data integrity. It is essential for users of affected versions to apply necessary patches and updates to mitigate this risk. For further information, refer to Bitdefender's advisory.

Affected Version(s)

GravityZone Console On-Premise 0 < 6.38.1-2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicolas VERDIER -- n1nj4sec
.