← Vulnerability feed

Vulnerability record · CVE-2014-5350 · published 19 August 2014

CVE-2014-5350: Bitdefender GravityZone directory traversal in Web Console and Update Server

Bitdefender · Gravityzone

Bitdefender GravityZone before 5.1.11.432 contains multiple directory traversal flaws. An unauthenticated remote attacker can supply dot-dot sequences in the id parameter of the Web Console download endpoint or in the default URI on Update Server port 7074 to read arbitrary files. Because the affected components are management and update services, exposed instances risk leaking configuration and credential material.

5.0 CVSS 2.0 Medium EPSS 64% · top 0.8% CWE-22 · Path traversal
5.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote file read with public exploit references and very high EPSS, though impact is limited to confidentiality and a fixed version exists.

What it is

Bitdefender GravityZone before 5.1.11.432 contains multiple directory traversal flaws. An unauthenticated remote attacker can supply dot-dot sequences in the id parameter of the Web Console download endpoint or in the default URI on Update Server port 7074 to read arbitrary files. Because the affected components are management and update services, exposed instances risk leaking configuration and credential material.

Impact

An attacker gains read access to arbitrary files on the GravityZone host, which can expose configuration, credentials or other sensitive data. There is no write or code execution impact described in the record.

Attack surface

Reachable over the network via HTTP requests to the Web Console download endpoint and to port 7074 on the Update Server. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.64 (99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.

What to do

  • Upgrade GravityZone to 5.1.11.432 or later, which the advisory names as the fixed build.
  • Restrict network access to the Web Console and to Update Server port 7074 using firewall rules, as Bitdefender's own guidance suggests.
  • Do not expose the management console or update service directly to untrusted networks; place them behind VPN or administrative segmentation.
  • After patching, rotate any credentials or secrets that may have been stored in files readable through the traversal.

Detection

  • Search web and update server logs for requests containing '..' or '%2E%2E' in the URI or id parameter.
  • Alert on access to the webservice/CORE/downloadFullKitEpc path with unexpected id values.
  • Monitor port 7074 for requests with encoded traversal sequences from external or unusual source addresses.
  • Review outbound or file-read behavior from the GravityZone host for signs of configuration file access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-5350 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-3554Bitdefender endpoint security tools improper access control vulnerabilityImproper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows…EPSS 2.6%9.8CVE-2024-4177Bitdefender gravityzone server-side request forgery (ssrf) vulnerabilityA host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request for…EPSS 0.43%9.8CVE-2022-2830Bitdefender gravityzone deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass uns…EPSS 0.92%9.8CVE-2021-3823Bitdefender gravityzone path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone…EPSS 1.1%9.8CVE-2017-8931Bitdefender gravityzone vulnerabilityBitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.EPSS 1.5%9.8CVE-2018-8955Bitdefender gravityzone improper verification of cryptographic signature vulnerabilityThe installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remo…EPSS 4.3%9.5CVE-2025-2244Bitdefender gravityzone deserialization of untrusted data vulnerabilityA vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on u…EPSS 1.1%9.2CVE-2024-6980Bitdefender gravityzone error message information leak vulnerabilityA verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request fo…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2014-5350), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.