216.73.216.233

CVE-2025-2243

· Published 04/04/2025 10:15 · Modified 04/04/2025 10:15

Labels: CVE-2025-2243 2025-04-04CVE-2025-2243CWE-918[email protected]

Essential information

Published
04/04/2025 10:15
Modified
04/04/2025 10:15
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests. Paired with other potential vulnerabilities, this bypass could be used for execution of third party code. This issue affects GravityZone Console: before 6.41.2.1.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bitdefender / gravityzone console cpe:2.3:a:bitdefender:gravityzone_console:<6.41.2.1:*:*:*:*:*:*:*

References