CVE-2024-13870 is an improper access control vulnerability affecting Bitdefender Box 1 devices running firmware version 1.3.52.928 and below. An unauthenticated attacker within Wi-Fi range can force the device into Recovery Mode and downgrade its firmware to an older, potentially vulnerable Bitdefender-signed version. This medium-severity vulnerability (CVSS 5.7) requires physical proximity and user interaction for exploitation, leading to high integrity impact but no confidentiality or availability impact. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.52.928CPE matchmatch criteria | cpe:2.3:o:bitdefender:box_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Unauthenticated Firmware Downgrade in Bitdefender Box v1
Mar 12, 2025Unauthenticated Firmware Downgrade in Bitdefender Box v1
Mar 12, 2025Unauthenticated Firmware Downgrade in Bitdefender Box v1
Mar 12, 2025Unauthenticated Firmware Downgrade in Bitdefender Box v1
Mar 12, 2025Unauthenticated Firmware Downgrade in Bitdefender Box v1
Mar 12, 2025