Vulnerability record · CVE-2014-5350 · published 19 August 2014
CVE-2014-5350: Bitdefender GravityZone directory traversal in Web Console and Update Server
Bitdefender · Gravityzone
Bitdefender GravityZone before 5.1.11.432 contains multiple directory traversal flaws. An unauthenticated remote attacker can supply dot-dot sequences in the id parameter of the Web Console download endpoint or in the default URI on Update Server port 7074 to read arbitrary files. Because the affected components are management and update services, exposed instances risk leaking configuration and credential material.
Description
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file read with public exploit references and very high EPSS, though impact is limited to confidentiality and a fixed version exists.
What it is
Bitdefender GravityZone before 5.1.11.432 contains multiple directory traversal flaws. An unauthenticated remote attacker can supply dot-dot sequences in the id parameter of the Web Console download endpoint or in the default URI on Update Server port 7074 to read arbitrary files. Because the affected components are management and update services, exposed instances risk leaking configuration and credential material.
Impact
An attacker gains read access to arbitrary files on the GravityZone host, which can expose configuration, credentials or other sensitive data. There is no write or code execution impact described in the record.
Attack surface
Reachable over the network via HTTP requests to the Web Console download endpoint and to port 7074 on the Update Server. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.64 (99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Upgrade GravityZone to 5.1.11.432 or later, which the advisory names as the fixed build.
- Restrict network access to the Web Console and to Update Server port 7074 using firewall rules, as Bitdefender's own guidance suggests.
- Do not expose the management console or update service directly to untrusted networks; place them behind VPN or administrative segmentation.
- After patching, rotate any credentials or secrets that may have been stored in files readable through the traversal.
Detection
- Search web and update server logs for requests containing '..' or '%2E%2E' in the URI or id parameter.
- Alert on access to the webservice/CORE/downloadFullKitEpc path with unexpected id values.
- Monitor port 7074 for requests with encoded traversal sequences from external or unusual source addresses.
- Review outbound or file-read behavior from the GravityZone host for signs of configuration file access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-5350 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-5350), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.