CVE-2020-0602
published 2020-01-14CVE-2020-0602: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
7.61%
93.9th percentile
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.1 | 3.1.1 |
| msrc | asp.net_core_2.1 | — | — |
| msrc | asp.net_core_3.0 | — | — |
| msrc | asp.net_core_3.1 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: Denial of service via backpressure issue
vendor_redhat·2020-01-14·CVSS 7.5
CVE-2020-0602 [HIGH] CWE-400 dotnet: Denial of service via backpressure issue
dotnet: Denial of service via backpressure issue
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
A denial of service flaw was found in ASP.NET Core. An unauthenticated, remote attacker could exploit this vulnerability by sending specially crafted requests to an ASP.NET Core application. The highest threat from this flaw is system availability.
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet22 (.NET Core 2.2 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet3.1 (Red Hat Enterprise Linux 8) - Not affected
Microsoft
ASP.NET Core Denial of Service Vulnerability
vendor_msrc·2020-01-14·CVSS 7.5
CVE-2020-0602 [HIGH] ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application.
The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
ASP.NET: ASP.NET
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:P
OSV
Denial of service in ASP.NET Core
osv·2022-05-24
CVE-2020-0602 [MEDIUM] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
GHSA
Denial of service in ASP.NET Core
ghsa·2022-05-24
CVE-2020-0602 [MEDIUM] CWE-400 Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
No detection rules found.
No public exploits indexed.
Trendmicro
January Patch Tuesday: IE, RDP, Crypto Bugs Updates
blogs_trendmicro·2020-01-15·CVSS 9.8
[CRITICAL] January Patch Tuesday: IE, RDP, Crypto Bugs Updates
## January Patch Tuesday: IE, RDP, Crypto Bugs Updates
Microsoft released 49 patches in this cycle, eight of which are classifed Critical and the remaining 41 as Important. The fixes address a range of products, including RDP Gateway servers, Internet Explorer, CryptoAPI, Office, and OneDrive.
By: Trend Micro 2020/01/15 Read time: ( words)
Save to Folio
2020 starts off with a relatively heavy list of patches for Microsoft users. January is typically a light month for fixes, but Microsoft released patches for 49 vulnerabilities (eight of which are Critical and all the remaining classified as Important) in this cycle. None of these vulnerabilities are known to be under attack at this time.
The listed vulnerabilities covered a range of Microsoft products including Windows RDP Gateway ser
Trendmicro
January Patch Tuesday: IE, RDP, Crypto Bugs Updates
blogs_trendmicro·2020-01-15·CVSS 9.8
[CRITICAL] January Patch Tuesday: IE, RDP, Crypto Bugs Updates
## January Patch Tuesday: IE, RDP, Crypto Bugs Updates
Microsoft released 49 patches in this cycle, eight of which are classifed Critical and the remaining 41 as Important. The fixes address a range of products, including RDP Gateway servers, Internet Explorer, CryptoAPI, Office, and OneDrive.
By: Trend Micro Jan 15, 2020 Read time: ( words)
Save to Folio
2020 starts off with a relatively heavy list of patches for Microsoft users. January is typically a light month for fixes, but Microsoft released patches for 49 vulnerabilities (eight of which are Critical and all the remaining classified as Important) in this cycle. None of these vulnerabilities are known to be under attack at this time.
The listed vulnerabilities covered a range of Microsoft products including Windows RDP Gateway s
Trendmicro
January Patch Tuesday: IE, RDP, Crypto Bugs Updates
blogs_trendmicro·2020-01-15·CVSS 9.8
[CRITICAL] January Patch Tuesday: IE, RDP, Crypto Bugs Updates
# January Patch Tuesday: IE, RDP, Crypto Bugs Updates
Microsoft released 49 patches in this cycle, eight of which are classifed Critical and the remaining 41 as Important. The fixes address a range of products, including RDP Gateway servers, Internet Explorer, CryptoAPI, Office, and OneDrive.
By: Trend Micro
2020/01/15
Read time: ( words)
Save to Folio
2020 starts off with a relatively heavy list of patches for Microsoft users. January is typically a light month for fixes, but Microsoft released patches for 49 vulnerabilities (eight of which are Critical and all the remaining classified as Important) in this cycle. None of these vulnerabilities are known to be under attack at this time.
The listed vulnerabilities covered a range of Microsoft products including Windows RDP Gateway ser
Talos
Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-01-14·CVSS 8.1
CVE-2020-0601 [HIGH] Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw. Updated January 15th: Added an Advanced Custom Detection (ACD) signature for AMP that can be used to detect exploitation of CVE-2020-0601 by spoofing certificates masquerading as a Microsoft ECC Code Signing Certificate Authority.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 49 vulnerabilities, eight of which are considered critical.
This month's security update is particularly important for its disclosure of two vulnerabilities related to a core cryptographic component in all versions of Windows. CVE-2020-0601 could allow an attacker to use cryptography
Talos
Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-01-14·CVSS 8.1
CVE-2020-0601 [HIGH] Microsoft Patch Tuesday — Jan. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Updated January 15th: Added an Advanced Custom Detection (ACD) signature for AMP that can be used to detect exploitation of CVE-2020-0601 by spoofing certificates masquerading as a Microsoft ECC Code Signing Certificate Authority.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 49 vulnerabilities, eight of which are considered critical.
This month's security update is particularly important for its disclosure of two vulnerabilities related to a core cryptographic component in all versions of Windows. CVE-2020-0601 could allow an attacker to use cryptography to sign a malicious executable, making the file appear as if it was from a trusted sou
Bugzilla
CVE-2020-0602 dotnet: Denial of service via backpressure issue
bugzilla·2020-01-09·CVSS 7.5
CVE-2020-0602 [HIGH] CVE-2020-0602 dotnet: Denial of service via backpressure issue
CVE-2020-0602 dotnet: Denial of service via backpressure issue
A vulnerability related to the processing of web requests has been reported in ASP.NET Core. An unauthenticated remote attacker could exploit this vulnerability to cause a Denial of Service by sending specially crafted requests to an ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
https://github.com/aspnet/Announcements/issues/402
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:0130 https://access.redhat.com/errata/RHSA-2020:0130
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:0134 https://access.redhat.com/e
https://access.redhat.com/errata/RHSA-2020:0130https://access.redhat.com/errata/RHSA-2020:0134https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602https://access.redhat.com/errata/RHSA-2020:0130https://access.redhat.com/errata/RHSA-2020:0134https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
2020-01-14
Published