CVE-2025-2245

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 121
CWE ID 787

Summary

CVE-2025-2245 is a server-side request forgery (SSRF) vulnerability discovered in Bitdefender GravityZone Update Server while operating in Relay Mode. The HTTP proxy component on port 7074 employs a domain allowlist to restrict outbound requests but falls short in sanitizing hostnames with null-byte (%00) sequences. Maliciously crafted requests to a domain such as evil.com%00.bitdefender.com enable an attacker to circumvent the allowlist check, leading to unauthorized forwarding of requests to arbitrary external or internal systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Neurons For Zero-trust Access
  • Ivanti Connect Secure
  • Ivanti Policy Secure

Affected Vendors

  • Ivanti