SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-1306

Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server…

LOW 2.6EPSS 1.28%

Does this matter?

Lower severity and a low EPSS score (1.28%). Track it; it rarely justifies an emergency change on its own.

Description

Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
1.28% probability · 68th percentile
CISA KEV
Not listed
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.