An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.
History

Wed, 12 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Mar 2025 12:00:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.
Title Unauthenticated Firmware Downgrade in Bitdefender Box v1
Weaknesses CWE-1328
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2025-03-12T14:01:55.166Z

Reserved: 2025-02-13T17:36:42.145Z

Link: CVE-2024-13870

cve-icon Vulnrichment

Updated: 2025-03-12T14:01:49.878Z

cve-icon NVD

Status : Received

Published: 2025-03-12T12:15:12.443

Modified: 2025-03-12T12:15:12.443

Link: CVE-2024-13870

cve-icon Redhat

No data.