CVE-2018-8171
high · 7.5A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
7.5
CVSS
10.5%
EPSS (exploit prob.)
95th
EPSS percentile
2018-07-11
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | asp.net_core | 1.0 |
| microsoft | asp.net_core | 1.1 |
| microsoft | asp.net_core | 2.0 |
| microsoft | asp.net_model_view_controller | 5.2 |
| microsoft | asp.net_webpages | 3.2.3 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/104659
- http://www.securitytracker.com/id/1041267
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171
- http://www.securityfocus.com/bid/104659
- http://www.securitytracker.com/id/1041267
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-8171