VendorsBitdefendergravityzoneall versions
Vulnerabilities

Bitdefender Gravityzone

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2021-3554
Improper Access Control vulnerability in the patchesUpdate API
Published 2021-11-24 · Modified
10.0EPSS 0.026
CVE-2017-8931
Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.
Published 2018-10-30 · Modified
10.0EPSS 0.015
CVE-2018-8955
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
Published 2018-10-24 · Modified
9.8EPSS 0.043
CVE-2025-2244
Insecure PHP deserialization issue in GravityZone Console (VA-12634)
Published 2025-04-04 · Analyzed
9.8EPSS 0.011
CVE-2021-3823
Path traversal vulnerability in Bitdefender GravitZone Update Server in relay mode
Published 2021-10-28 · Modified
9.8EPSS 0.011
CVE-2022-2830
Deserialization of Untrusted Data in GravityZone Console On-Premise (VA-10573)
Published 2022-09-05 · Modified
9.8EPSS 0.009
CVE-2024-6980
Verbose error handling issue in GravityZone Update Server proxy service
Published 2024-07-31 · Analyzed
9.8EPSS 0.006
CVE-2024-4177
Host whitelist parser issue in GravityZone Console On-Premise (VA-11554)
Published 2024-06-06 · Modified
9.8EPSS 0.004
CVE-2021-3960
Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-10146)
Published 2021-12-16 · Modified
7.8EPSS 0.003
CVE-2021-3959
Server-Side Request Forgery in Bitdefender GravityZone Update Server in Relay Mode (VA-10145)
Published 2021-12-16 · Modified
7.5EPSS 0.017
CVE-2021-3552
Insufficient validation on regular expression in EPPUpdateService config file (VA-9825)
Published 2021-11-24 · Modified
7.5EPSS 0.013
CVE-2021-3553
Server-Side Request Forgery in EPPUpdateService remote config file (VA-9825)
Published 2021-11-24 · Modified
7.5EPSS 0.013
CVE-2022-0677
Improper Handling of Length Parameter Inconsistency vulnerability in Bitdefender Update Server (VA-10144)
Published 2022-04-07 · Modified
7.5EPSS 0.012
CVE-2025-2243
SSRF in GravityZone Console via DNS Truncation (VA-12634)
Published 2025-04-04 · Analyzed
7.3EPSS 0.004
CVE-2021-3641
Improper Link Resolution Before File Access in Bitdefender GravityZone (VA-9921)
Published 2021-11-09 · Modified
6.1EPSS 0.004
CVE-2014-5350
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.
Published 2014-08-19 · Modified
5.01 PoCEPSS 0.639