Private IP address disclosure

Info Web Application Scanning Plugin ID 98077


Private IP address disclosure


Private, or non-routable, IP addresses are generally used within a home or company network and are typically unknown to anyone outside of that network.

Cyber-criminals will attempt to identify the private IP address range being used by their victim, to aid in collecting further information that could then lead to a possible compromise.

Scanner discovered that the affected page returned a RFC 1918 compliant private IP address and therefore could be revealing sensitive information.

This finding typically requires manual verification to ensure the context is correct, as any private IP address within the HTML body will trigger it.


Identifying the context in which the affected page displays a Private IP address is necessary.
If the page is publicly accessible and displays the Private IP of the affected server (or supporting infrastructure), then measures should be put in place to ensure that the IP address is removed from any response.

See Also

Plugin Details

Severity: Info

ID: 98077

Type: remote

Published: 2017/03/31

Updated: 2020/07/09

Scan Template: api, scan, pci, overview

Risk Information

Risk Factor: Info