cbcvebase.
CVE-2018-8171
published 2018-07-11

CVE-2018-8171: A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass…

PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
9.83%
95.0th percentile
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

Affected

20 ranges
VendorProductVersion rangeFixed in
microsoftasp.net
microsoftasp.net
microsoftasp.net_core
microsoftasp.net_core
microsoftasp.net_core
microsoftasp.net_model_view_controller
microsoftasp.net_mvc_5.2
microsoftasp.net_mvc_5.2
microsoftasp.net_webpages
microsoftmicrosoft.aspnetcore.identity>= 1.0.0 < 1.0.61.0.6
microsoftmicrosoft.aspnetcore.identity>= 1.1.0 < 1.1.61.1.6
microsoftmicrosoft.aspnetcore.identity>= 2.0.0 < 2.0.42.0.4
microsoftmicrosoft.aspnetcore.identity>= 2.1.0 < 2.1.22.1.2
msrcasp.net_core_1.0
msrcasp.net_core_1.1
msrcasp.net_core_2.0
msrcasp.net_mvc_5.2_on_microsoft_visual_studio_2013_update_5
msrcasp.net_mvc_5.2_on_microsoft_visual_studio_2015_update_3
msrcasp.net_web_pages_3.2.3_on_microsoft_visual_studio_2013_update_5
msrcasp.net_web_pages_3.2.3_on_microsoft_visual_studio_2015_update_3

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.