cbcvebase.
CVE-2018-8171
published 2018-07-11

CVE-2018-8171: A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass…

high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

Affected

20 ranges
VendorProductVersion rangeFixed in
microsoftasp.net
microsoftasp.net
microsoftasp.net_core
microsoftasp.net_core
microsoftasp.net_core
microsoftasp.net_model_view_controller
microsoftasp.net_mvc_5.2
microsoftasp.net_mvc_5.2
microsoftasp.net_webpages
microsoftmicrosoft.aspnetcore.identity>= 1.0.0 < 1.0.61.0.6
microsoftmicrosoft.aspnetcore.identity>= 1.1.0 < 1.1.61.1.6
microsoftmicrosoft.aspnetcore.identity>= 2.0.0 < 2.0.42.0.4
microsoftmicrosoft.aspnetcore.identity>= 2.1.0 < 2.1.22.1.2
msrcasp.net_core_1.0
msrcasp.net_core_1.1
msrcasp.net_core_2.0
msrcasp.net_mvc_5.2_on_microsoft_visual_studio_2013_update_5
msrcasp.net_mvc_5.2_on_microsoft_visual_studio_2015_update_3
msrcasp.net_web_pages_3.2.3_on_microsoft_visual_studio_2013_update_5
msrcasp.net_web_pages_3.2.3_on_microsoft_visual_studio_2015_update_3