CVE-2022-2830

HIGH

Bitdefender GravityZone <6.29.2-1, <6.27.2-2 - Deserialization

Title source: llm
STIX 2.1

Description

Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.

Scores

CVSS v3 8.8
EPSS 0.0076
EPSS Percentile 50.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
bitdefender/gravityzone < 6.27.2-2
bitdefender/gravityzone < 6.29.2-1
Published Sep 05, 2022
Tracked Since Feb 18, 2026