Описание
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.4.1 (включая)Версия до 4.1.3 (включая)
Одно из
cpe:2.3:a:ipmatcher_project:ipmatcher:*:*:*:*:*:*:*:*
cpe:2.3:a:watsonwebserver_project:watsonwebserver:*:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00743
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-704
Связанные уязвимости
EPSS
Процентиль: 73%
0.00743
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-704