Описание
.NET Denial of Service Vulnerability
A denial of service vulnerability exists in .NET applications with OpenSSL support when parsing X509 certificates. The issue arises from inadequate validation of user-supplied input in .NET. This flaw allows a remote attacker to trigger a denial of service (DoS) attack by providing specially crafted input.
Дополнительная информация
Статус:
Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2263086dotnet: Denial of Service in X509Certificate2
EPSS
Процентиль: 87%
0.03637
Низкий
7.5 High
CVSS3
EPSS
Процентиль: 87%
0.03637
Низкий
7.5 High
CVSS3