Описание
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
A flaw exists in certain .NET builds where a man-in-the-middle (MITM) attacker can prevent or downgrade TLS between a client and an SMTP server. This may cause the client to send credentials or message data over an unencrypted connection, exposing sensitive information to the attacker.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as High, given that it can be remotely exploited by a man-in-the-middle attacker without authentication or user interaction. Successful exploitation allows an attacker to disable TLS protection between a .NET client and an SMTP server, leading to exposure of credentials and message contents over an unencrypted connection. The vulnerability results from insufficient enforcement of TLS during SMTP session negotiation in the affected .NET runtime.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet10.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet6.0 | Out of support scope | ||
| Red Hat Enterprise Linux 9 | dotnet7.0 | Out of support scope | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2025:18152 | 15.10.2025 |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2025:18153 | 15.10.2025 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2025:18148 | 15.10.2025 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2025:18150 | 15.10.2025 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2025:18149 | 15.10.2025 |
| Red Hat Enterprise Linux 9 | dotnet9.0 | Fixed | RHSA-2025:18151 | 15.10.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
.NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Уязвимость программных платформ Microsoft .NET Framework, .NET и средства разработки программного обеспечения Microsoft Visual Studio, связанная с недостаточно стойким шифрованием данных, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
8.2 High
CVSS3