CVE-2025-2243 MEDIUM

CVE-2025-2243: SSRF in GravityZone Console via DNS Truncation (VA-12634)

Vendor Bitdefender
Product GravityZone Console
Weakness CWE-918 · SSRF
Published April 4, 2025
Last update April 4, 2025

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

What the vulnerability does

01Description

A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests. Paired with other potential vulnerabilities, this bypass could be used for execution of third party code. This issue affects GravityZone Console: before 6.41.2.1.

Key dates

02Disclosure timeline

April 4, 2025 CVE published
April 4, 2025 Record updated