CVE-2024-13872
HIGHBitdefender Box Firmware < 1.3.11.505 - Cleartext Transmission
Title source: ruleDescription
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent attacker can use man-in-the-middle (MITM) techniques to return malicious responses. Restarted daemons that use malicious assets can then be exploited for remote code execution on the device.
Scores
CVSS v3
7.5
EPSS
0.0138
EPSS Percentile
80.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-319
Status
published
Products (1)
bitdefender/box_firmware
1.3.11.490 - 1.3.11.505
Published
Mar 12, 2025
Tracked Since
Feb 18, 2026