Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-4963

20
FAUCET Score

CVE-2011-4963 describes an access restriction bypass vulnerability in nginx for Windows versions 1.3.x before 1.3.1 and 1.2.x before 1.2.1, allowing remote attackers to access restricted files through malformed requests. This vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and potential for partial confidentiality impact, but no integrity or availability impact. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.7.52, < 1.2.1CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
1.3.0CPE matchmatch criteria
cpe:2.3:a:f5:nginx:1.3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.96%
Probability of exploitation in next 30 days
EPSS Percentile
92.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0596 is in the 89th percentile among its peer group of 23,684 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

netgearpatch availablevia llm_extracted
Fixed in: 1.3.1+, 1.2.1+
opensshpatch availablevia llm_extracted
Fixed in: 1.3.1
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.2.1
terraformpatch availablevia llm_extracted
Fixed in: 1.3.1
dahuavendor investigatingvia llm_extracted
Fixed in: 1.2.1+
dfinityvendor investigatingvia llm_extracted
Fixed in: 1.3.1
jfrogvendor investigatingvia llm_extracted
Fixed in: 1.3.1
liferayvendor investigatingvia llm_extracted
Fixed in: 1.2.1

Vendor Advisories (8)

liferayllm-liferay-e2707685d9484c10MEDIUM

Vulnerabilities with Windows directory aliases

Jan 1, 2012
jfrogllm-jfrog-b50c1b5d4d848314MEDIUM

Vulnerabilities with Windows directory aliases

Jan 1, 2011
opensshllm-openssh-8e75fbee46c73e13MEDIUM

Vulnerabilities with Windows directory aliases

Jan 1, 2011
power_billm-power_bi-0ecf69491bd17484MEDIUM

Vulnerabilities with Windows directory aliases

Jan 1, 2011
dfinityllm-dfinity-cc81fb1182d2e7f8MEDIUM

Vulnerabilities with Windows directory aliases

Jan 1, 2011
dahuallm-dahua-34215c51c0d92b93MEDIUM

Vulnerabilities with Windows directory aliases

terraformllm-terraform-6598f0ad6f8bb037MEDIUM

Vulnerabilities with Windows directory aliases

netgearllm-netgear-6a0734003b149613MEDIUM

Vulnerabilities with Windows directory aliases

References

english.securitylab.ru / lab/PT-2012-06
MitigationThird Party Advisory
mailman.nginx.org / pipermail/nginx-announce/2012/000086.html
MitigationVendor Advisory
nginx.org / en/security_advisories.html
Vendor Advisory