📦 Gravityzone

by Bitdefender

🔍 What is Gravityzone?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2244

CRITICAL CVSS 9.8 Apr 4, 2025

This vulnerability allows remote attackers to execute arbitrary code on Bitdefender GravityZone Console servers by exploiting insecure PHP deserialization. Attackers can achieve full system compromise...

CVE-2024-6980

CRITICAL CVSS 9.8 Jul 31, 2024

A verbose error handling issue in the GravityZone Update Server proxy service allows attackers to perform server-side request forgery (SSRF) attacks. This vulnerability affects on-premise deployments ...

CVE-2021-3554

CRITICAL CVSS 9.0 Nov 24, 2021

This vulnerability allows attackers to manipulate the remote address used for pulling patches in Bitdefender's patchesUpdate API on Linux systems configured as relays. Attackers could redirect patch d...

CVE-2025-2243

HIGH CVSS 7.3 Apr 4, 2025

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows attackers to bypass input validation using leading characters in DNS requests. This could enable internal n...

CVE-2024-4177

HIGH CVSS 8.1 Jun 6, 2024

A host whitelist parser vulnerability in the GravityZone Update Server proxy service allows attackers to perform server-side request forgery (SSRF). This affects only on-premise deployments of Gravity...

CVE-2022-0677

HIGH CVSS 7.5 Apr 7, 2022

This vulnerability allows an attacker to cause a Denial-of-Service (DoS) in Bitdefender's Update Server and GravityZone components by exploiting improper handling of length parameter inconsistencies. ...

CVE-2021-3960

HIGH CVSS 7.1 Dec 16, 2021

This path traversal vulnerability in Bitdefender GravityZone's UpdateServer component allows attackers to escape restricted directories and execute arbitrary code on vulnerable systems. It affects Bit...