CVE-2024-13872 affects Bitdefender Box versions 1.3.11.490 through 1.3.11.505, allowing an unauthenticated, network-adjacent attacker to achieve remote code execution. The vulnerability stems from the device using unencrypted HTTP to download updates, enabling man-in-the-middle (MITM) attacks to inject malicious assets. With a CVSS score of 7.5 (HIGH), this flaw presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.11.490, <= 1.3.11.505CPE matchmatch criteria | cpe:2.3:o:bitdefender:box_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Insecure Update Mechanism Vulnerability in libboxhermes.so in Bitdefender BOX v1
Mar 12, 2025Insecure Update Mechanism Vulnerability in libboxhermes.so in Bitdefender BOX v1
Mar 12, 2025Insecure Update Mechanism Vulnerability in libboxhermes.so in Bitdefender BOX v1
Mar 12, 2025Insecure Update Mechanism Vulnerability in libboxhermes.so in Bitdefender BOX v1
Mar 12, 2025Insecure Update Mechanism Vulnerability in libboxhermes.so in Bitdefender BOX v1
Mar 12, 2025