ZeroHour

CVE-2018-8171

CVSS 3.0
7.5 high
EPSS
10%p95
Published
()
Modified
Description

A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

Vendors
microsoft
Products
asp.net core, asp.net model view controller, asp.net webpages
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news