Cyber Resilience

CVE-2024-13870

Bitdefender Box Firmware ≤ 1.3.52.928

Published
12 March 2025
Modified
30 July 2025
Patch / advisory
CVSS Score v4 1.8
Click a component to see what it means
Raw vectorCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X
EPSS Score 0.0016 6th percentile
Risk Priority 15 floored blend · peak EPSS

Summary

CVE-2024-13870 is a low-severity Security Version Number Mutable to Older Versions (CWE-1328) vulnerability in Bitdefender Box Firmware. Its CVSS base score is 1.8 (Low).

Operationally, exploitation aligns with the MITRE ATT&CK technique Downgrade Attack (T1689); ranked at the 6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SC-51 (Hardware-based Protection) and SI-7 (Software, Firmware, and Information Integrity) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX…

more

to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1689 Downgrade Attack Defense Impairment
Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2024-13871Same product: Bitdefender Box
CVE-2024-13872Same product: Bitdefender Box
CVE-2025-29989Shared CWE-1328
CVE-2025-8321Shared CWE-1328
CVE-2025-5825Shared CWE-1328
CVE-2024-11128Same vendor: Bitdefender
CVE-2024-2224Same vendor: Bitdefender
CVE-2023-6154Same vendor: Bitdefender
CVE-2023-49570Same vendor: Bitdefender
CVE-2024-2223Same vendor: Bitdefender

Affected Assets

bitdefender
box firmware
≤ 1.3.52.928

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

Hardware-enforced write protection directly stops unauthorized mutation of a security version number to older values.

Firmware integrity verification can discover that a version rollback has occurred after the fact.

Enforcing access restrictions on configuration changes can block unauthorized writes to a mutable security version register.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

ID.RA-09 mostly match
prevents

Pre-acquisition assessment of hardware authenticity/integrity directly prevents purchase of chips whose security version numbers can be rolled back.

PR.PS-01 partial match
prevents

Hardened baselines and configuration management can enforce immutable version checks or secure-boot policies that mitigate rollback.

PR.PS-03 partial match
prevents

Hardware lacking immutable version-number protection can be identified and replaced as part of risk-based hardware maintenance.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

degrades

Controlled software installation procedures can block unauthorized or older firmware versions from being loaded.

prevents

Secure SDLC practices can embed anti-rollback mechanisms during hardware/firmware design.

prevents

Secure architecture principles can mandate hardware-enforced version counters or fuses.

degrades

Change-management processes can require cryptographic verification of firmware versions before deployment.

degrades

Configuration management can enforce immutable or version-locked firmware images, limiting rollback risk.

References