CVE-2021-3485
Bitdefender Endpoint Security Tools vulnerability analysis and mitigation

Overview

CVE-2021-3485 is an Improper Input Validation vulnerability discovered in the Product Update feature of Bitdefender Endpoint Security Tools for Linux. The vulnerability was identified on April 7, 2021, and publicly disclosed on May 24, 2021. It affects Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155 (Bitdefender Advisory).

Technical details

The vulnerability exists in the DownloadFile function of the product-update bash script, which uses wget with the --no-check-certificate flag for downloading updates. The implementation uses an insecure channel for communication, and the update mechanism called 'product-update' performs downloads over HTTP instead of HTTPS. The vulnerability has been assigned a CVSS v3.1 base score of 6.4 (Medium) with the vector string CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H (HeroLab Advisory, Bitdefender Advisory).

Impact

If successfully exploited, this vulnerability allows an attacker in a man-in-the-middle position to achieve remote code execution with root privileges on the affected system (HeroLab Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Bitdefender Endpoint Security Tools for Linux version 6.2.21.155. An automatic update to this version addresses the issue. The vendor recommends implementing industry-proven schemes for software updates, including using secure communication channels and signing update binaries with manufacturer private keys (Bitdefender Advisory, HeroLab Advisory).

Additional resources


SourceThis report was generated using AI

Related Bitdefender Endpoint Security Tools vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-2224CRITICAL9.8
  • Bitdefender Endpoint Security ToolsBitdefender Endpoint Security Tools
  • cpe:2.3:a:bitdefender:endpoint_security_tools
NoYesApr 09, 2024
CVE-2024-2223CRITICAL9.8
  • Bitdefender Endpoint Security ToolsBitdefender Endpoint Security Tools
  • cpe:2.3:a:bitdefender:endpoint_security_tools
NoYesApr 09, 2024
CVE-2021-4199HIGH7.8
  • Bitdefender Internet SecurityBitdefender Internet Security
  • cpe:2.3:a:bitdefender:endpoint_security_tools
NoYesMar 07, 2022
CVE-2022-0677HIGH7.5
  • Bitdefender Endpoint Security ToolsBitdefender Endpoint Security Tools
  • cpe:2.3:a:bitdefender:endpoint_security_tools
NoYesApr 07, 2022
CVE-2021-4198MEDIUM6.1
  • Bitdefender Internet SecurityBitdefender Internet Security
  • cpe:2.3:a:bitdefender:endpoint_security_tools
NoYesMar 07, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management