CVE-2019-1301

Severity
7.5HIGH
EPSS
2.8%
top 13.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateNov 12

Description

A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5microsoft/.net_core2.1, 2.2+1
NVDmicrosoft/.net_core2.1, 2.2+1
NuGetSystem.Management.Automation6.2.06.2.3+1

Patches

🔴Vulnerability Details

3
OSV
High severity vulnerability that affects System.Management.Automation2019-09-13
GHSA
High severity vulnerability that affects System.Management.Automation2019-09-13
CVEList
CVE-2019-1301: A denial of service vulnerability exists when2019-09-11

📋Vendor Advisories

2
Microsoft
.NET Core Denial of Service Vulnerability2019-09-10
Red Hat
dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service2019-09-10

💬Community

2
Bugzilla
CVE-2019-14463 libmodbus: out-of-bounds read in MODBUS_FC_WRITE_MULTIPLE_COILS2019-11-12
Bugzilla
CVE-2019-1301 dotnet: System.Net.Sockets.dll Socket.ConnectAsync Denial of Service2019-09-10