CVE-2002-1484

CRITICALCVSS 9.8/10EPSS 13.66%

Last modified

CVE-2002-1484 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.. EPSS estimates a 13.66% chance of exploitation in the next 30 days.

Description

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
13.66%

96.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SiemensDb4web3.4
SiemensDb4web3.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2002-1484?
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
How severe is CVE-2002-1484?
CVE-2002-1484 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 13.66% probability of exploitation in the next 30 days.
How do I fix CVE-2002-1484?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2002-1484?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST