Bitdefender BOX是罗马尼亚比特梵德(Bitdefender)公司的一款智能家居安全控制设备。 Bitdefender BOX 2 2.1.47.36之前版本中的恢复分区存在竞争条件问题漏洞,该漏洞源于API的‘/api/update_setup’方法不会自动执行固件签名检查。攻击者可利用该漏洞执行任意系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bitdefender | Bitdefender BOX 2 | unspecified ~ 2.1.47.36 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-17095 | 8.1 HIGH | Bitdefender BOX 2 bootstrap download_image command injection vulnerability |
| CVE-2019-17099 | 5.3 MEDIUM | Untrusted Search Path vulnerability in EPSecurityService.exe (VA-3500) |
| CVE-2019-17100 | 5.2 MEDIUM | Untrusted Search Path vulnerability in Bitdefender Total Security 2020 (VA-5895) |
| CVE-2019-17103 | 4.9 MEDIUM | Get-task-allow entitlement via BDLDaemon on macOS |
No comments yet