漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unauthenticated Firmware Downgrade in Bitdefender Box v1
Vulnerability Description
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:N
Vulnerability Type
CWE-1328
Vulnerability Title
Bitdefender Box 安全漏洞
Vulnerability Description
Bitdefender BOX是罗马尼亚比特梵德(Bitdefender)公司的一款智能家居安全控制设备。 Bitdefender Box 1.3.52.928及之前版本存在安全漏洞,该漏洞源于访问控制不当,可能导致未经身份验证的攻击者降级设备固件。
CVSS Information
N/A
Vulnerability Type
N/A