Описание
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:asp.net_core:1.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:asp.net_core:1.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:asp.net_core:2.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:asp.net_model_view_controller:5.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:asp.net_webpages:3.2.3:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.16829
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 7.5
github
больше 7 лет назад
Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated
EPSS
Процентиль: 95%
0.16829
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287