CVE-2020-15297

HIGH

Bitdefender Endpoint Security Tools <6.6.20.294 - Auth Bypass

Title source: llm
STIX 2.1

Description

Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.

Scores

CVSS v3 7.1
EPSS 0.0085
EPSS Percentile 53.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
bitdefender/update_server < 6.6.20.294
Published Nov 09, 2020
Tracked Since Feb 18, 2026