CVE-2021-33318
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-704
- Affected
- ipmatcher project/ipmatcher · watsonwebserver project/watsonwebserver
- Source
- cve@mitre.org
References
- https://github.com/jchristn/IpMatcherThird Party Advisory
- https://github.com/jchristn/IpMatcher/commit/81d77c2f33aa912dbd032b34b9e184fc6e041d89Patch, Third Party Advisory
- https://github.com/jchristn/WatsonWebserverThird Party Advisory
- https://github.com/kaoudis/advisories/blob/main/0-2021.mdExploit, Third Party Advisory
- https://github.com/jchristn/IpMatcherThird Party Advisory
- https://github.com/jchristn/IpMatcher/commit/81d77c2f33aa912dbd032b34b9e184fc6e041d89Patch, Third Party Advisory
- https://github.com/jchristn/WatsonWebserverThird Party Advisory
- https://github.com/kaoudis/advisories/blob/main/0-2021.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.