Back

Bitdefender BOX Denial of Service (VA-3184)

Publication date: October 17th, 2019


CVE ID:
CVE-2019-12611
CVSS scrore:
4.4 - https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected vendors:
Bitdefender
Affected products:
Bitdefender BOX
Vulnerability details:

An issue was discovered in the miniupnpd component as used in the Bitdefender BOX firmware versions before 2.1.37.37-34, that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in Bitdefender BOX results in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.  In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX network.

Additional details:
The issue was resolved in Bitdefender BOX firmware version 2.1.37.37-34
Credit:
ERNW Research GmbH