cbcvebase.
CVE-2018-8171
published 2018-07-11

CVE-2018-8171: A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass…

PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
10.48%
95.6th percentile
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

Affected

20 ranges
VendorProductVersion rangeFixed in
microsoftasp.net——
microsoftasp.net——
microsoftasp.net_core——
microsoftasp.net_core——
microsoftasp.net_core——
microsoftasp.net_model_view_controller——
microsoftasp.net_mvc_5.2——
microsoftasp.net_mvc_5.2——
microsoftasp.net_webpages——
microsoftmicrosoft.aspnetcore.identity>= 1.0.0 < 1.0.61.0.6
microsoftmicrosoft.aspnetcore.identity>= 1.1.0 < 1.1.61.1.6
microsoftmicrosoft.aspnetcore.identity>= 2.0.0 < 2.0.42.0.4
microsoftmicrosoft.aspnetcore.identity>= 2.1.0 < 2.1.22.1.2
msrcasp.net_core_1.0——
msrcasp.net_core_1.1——
msrcasp.net_core_2.0——
msrcasp.net_mvc_5.2_on_microsoft_visual_studio_2013_update_5——
msrcasp.net_mvc_5.2_on_microsoft_visual_studio_2015_update_3——
msrcasp.net_web_pages_3.2.3_on_microsoft_visual_studio_2013_update_5——
msrcasp.net_web_pages_3.2.3_on_microsoft_visual_studio_2015_update_3——

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.