Server-Side Request Forgery Vulnerability in Bitdefender GravityZone
CVE-2025-2245
6.9MEDIUM
What is CVE-2025-2245?
A server-side request forgery vulnerabilities has been identified in the Bitdefender GravityZone Update Server while functioning in Relay Mode. The HTTP proxy on port 7074 implements an allowlist to manage outbound requests; however, it inadequately filters hostnames that contain null-byte sequences (%00). This flaw could allow an attacker to devise a request targeting a malicious domain like evil.com%00.bitdefender.com, circumventing the allowance checks. As a result, the proxy could inadvertently route requests to unintended external or internal locations, exposing systems to potential attack vectors.
Affected Version(s)
GravityZone Update Server 0 < 3.5.2.689
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nicolas Verdier (@n1nj4sec)
