---
cve: "CVE-2014-5350"
severity: "LOW"
cvss: 3.1
epss: "63.9%"
vendor: "n/a"
kev: false
exploited: false
published: "2014-08-19 19:55:05"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T02:37:21+02:00"
---

# CVE-2014-5350

> 3.1 LOW

## Beschreibung

Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.

## Exploit-Evidenz

- [EDB-34086 — BitDefender GravityZone 5.1.5.386 - Multiple Vulnerabilities](https://www.exploit-db.com/exploits/34086)

## Referenzen

- <https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140716-3_Bitdefender_GravityZone_Multiple_critical_vulnerabilities_v10.txt>
- <http://seclists.org/fulldisclosure/2014/Jul/78>
- <http://www.bitdefender.com/support/how-to-configure-iptables-firewall-rules-on-gravityzone-for-restricting-outside-access-to-mongodatabase-1265.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2014-5350) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
