CVE-2021-4433
KarjaSoft Sami HTTP Server vulnerability analysis and mitigation

Overview

A vulnerability was found in Karjasoft Sami HTTP Server 2.0 (Web Server), identified as CVE-2021-4433. The vulnerability affects the HTTP HEAD Request Handler component and was publicly disclosed on January 16, 2024. The issue has been classified as problematic, potentially leading to denial of service conditions (VulDB, NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue is classified under CWE-404 (Improper Resource Shutdown or Release). The vulnerability can be exploited remotely, and the manipulation of the HTTP HEAD Request Handler can lead to denial of service conditions (NVD).

Impact

The successful exploitation of this vulnerability results in denial of service conditions, primarily affecting the availability of the system. The attack can be launched remotely, and no special privileges are required to execute the exploit (VulDB).

Mitigation and workarounds

At the time of disclosure, there is no official patch or mitigation strategy available for this vulnerability. It is recommended to consider replacing the affected software with an alternative product until a fix is released (VulDB).

Additional resources


SourceThis report was generated using AI

Related KarjaSoft Sami HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2004-0292HIGH10
  • KarjaSoft Sami HTTP ServerKarjaSoft Sami HTTP Server
  • cpe:2.3:a:karjasoft:sami_http_server
NoNoNov 23, 2004
CVE-2021-4433HIGH7.5
  • KarjaSoft Sami HTTP ServerKarjaSoft Sami HTTP Server
  • cpe:2.3:a:karjasoft:sami_http_server
NoNoJan 18, 2024
CVE-2007-0548MEDIUM5
  • KarjaSoft Sami HTTP ServerKarjaSoft Sami HTTP Server
  • cpe:2.3:a:karjasoft:sami_http_server
NoNoJan 29, 2007

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management