A vulnerability has been identified in Bitdefender GravityZone Update Server. The vulnerability could allow an attacker to perform Server-Side Request Forgery (SSRF) on a target update server. The vulnerability (CVE-2024-6980) has a Critical CVSS 4.0 score of 9.2 out of 10.
CVE-2024-6980 is a verbose error logging issue in GravityZone Update Console sofware components prior to version 6.38.1-5. Attackers can exploit the logging issue to manipulate the server into producing arbitrary requests to any given third-party machine, making it possible to leak sensitive data or possibly even perform arbitrary command execution. This can severely compromise the security of the organization.
This issue affects customers with GravityZone Console versions prior to 6.38.1-5 running on-premises, thus excluding cloud-based instances.