An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.
References
Link | Resource |
---|---|
https://bitdefender.com/support/security-advisories/unauthenticated-firmware-downgrade-in-bitdefender-box-v1 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
30 Jul 2025, 00:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Bitdefender box Firmware
Bitdefender Bitdefender box |
|
CPE | cpe:2.3:o:bitdefender:box_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bitdefender:box:-:*:*:*:*:*:*:* |
|
References | () https://bitdefender.com/support/security-advisories/unauthenticated-firmware-downgrade-in-bitdefender-box-v1 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.7 |
Summary |
|
12 Mar 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-12 12:15
Updated : 2025-07-30 00:52
NVD link : CVE-2024-13870
Mitre link : CVE-2024-13870
CVE.ORG link : CVE-2024-13870
JSON object : View
Products Affected
bitdefender
- box_firmware
- box
CWE
CWE-1328
Security Version Number Mutable to Older Versions