CVE-2021-28918

Scores

EPSS

0.859high85.9%
0%20%40%60%80%100%

Percentile: 85.9%

CVSS

9.1critical3.x
0246810

CVSS Score: 9.1/10

All CVSS Scores

CVSS 3.x
9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS 2.0
6.4

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Description

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-20CWE-704

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: netmask

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:netmask_project:netmask:*:*:*:*:*:node.js:*:*",      "versionEndIncluding": "1.0.6",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list