PT-2024-38018 · Bitdefender · Gravityzone Console

CVE-2024-6980

·

Published

2024-07-31

·

Updated

2024-08-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GravityZone Console versions prior to 6.38.1-5
Description A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions running on premise.
Recommendations For GravityZone Console versions prior to 6.38.1-5, upgrade the affected component to version 6.38.1-5 or later to mitigate the risk. As a temporary workaround, consider restricting access to the proxy service to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6980

Affected Products

Gravityzone Console