CVE-2022-2830
Last modified
CVE-2022-2830 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Gravityzone | < 6.27.2-2 |
| Bitdefender | Gravityzone | < 6.29.2-1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2830?
How severe is CVE-2022-2830?
How do I fix CVE-2022-2830?
Are you affected by CVE-2022-2830?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
