CVE-2025-2245
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 121
CWE ID 787
Summary
CVE-2025-2245 is a server-side request forgery (SSRF) vulnerability discovered in Bitdefender GravityZone Update Server while operating in Relay Mode. The HTTP proxy component on port 7074 employs a domain allowlist to restrict outbound requests but falls short in sanitizing hostnames with null-byte (%00) sequences. Maliciously crafted requests to a domain such as evil.com%00.bitdefender.com enable an attacker to circumvent the allowlist check, leading to unauthorized forwarding of requests to arbitrary external or internal systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ivanti Neurons For Zero-trust Access
- Ivanti Connect Secure
- Ivanti Policy Secure
Affected Vendors
- Ivanti