SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0105

ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.

MEDIUM 5.0EPSS 2.58%

Does this matter?

Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.

Description

ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.58% probability · 84th percentile
CISA KEV
Not listed
Affected
port80 software/servermask
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.