CVE-2023-33170
published 2023-07-11CVE-2023-33170: ASP.NET and Visual Studio Security Feature Bypass Vulnerability
PriorityP349high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.98%
78.3th percentile
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 0 < 6.0.20 | 6.0.20 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 7.0.0 < 7.0.9 | 7.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 0 < 6.0.20 | 6.0.20 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens ST7 ScadaConnect
cisa_ics·2024-06-13·CVSS 7.5
[HIGH] Siemens ST7 ScadaConnect
ICS Advisory
##
Siemens ST7 ScadaConnect
Release DateJune 13, 2024
Alert CodeICSA-24-165-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: ST7 ScadaConnect
- Vulnerabilities: Integer Overflow or Wraparound, Double Free, Improper Certificate Validation, Inefficient Regular Ex
Ubuntu
.NET vulnerability
vendor_ubuntu·2023-07-11
CVE-2023-33170 .NET vulnerability
Title: .NET vulnerability
Summary: The maximum failed attempts security feature for .NET could be bypassed.
McKee-Harris, Matt Cotterell, and Jack Moran discovered that .NET did
not properly update account lockout maximum failed attempts. An
attacker could possibly use this issue to bypass the security feature
and attempt to guess more passwords for an account.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
vendor_msrc·2023-07-11·CVSS 8.1
CVE-2023-33170 [HIGH] CWE-362 ASP.NET and Visual Studio Security Feature Bypass Vulnerability
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition and also to take additional actions prior to exploitation to prepare the target environment.
ASP.NET and Visual Studio: ASP.NET and Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.2
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 ve
Red Hat
dotnet: race condition in Core SignInManager<TUser> PasswordSignInAsync method
vendor_redhat·2023-07-11·CVSS 8.1
CVE-2023-33170 [HIGH] CWE-362 dotnet: race condition in Core SignInManager<TUser> PasswordSignInAsync method
dotnet: race condition in Core SignInManager PasswordSignInAsync method
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
A vulnerability was found in dotNET applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords and bypass security restrictions. This flaw allows a remote attacker to bypass security features, causing an impact on confidentiality, integrity, and availability.
GHSA
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
ghsa·2023-07-11·CVSS 8.1
CVE-2023-33170 [HIGH] CWE-362 Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
# Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords.
## Discussion
Discussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334
### Mitigation factors
Microsoft has not identified any mitigating facto
OSV
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
osv·2023-07-11·CVSS 8.1
CVE-2023-33170 [HIGH] Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
# Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exist in ASP.NET Core applications where account lockout maximum failed attempts may not be immediately updated, allowing an attacker to try more passwords.
## Discussion
Discussion for this issue can be found at https://github.com/dotnet/aspnetcore/issues/49334
### Mitigation factors
Microsoft has not identified any mitigating facto
OSV
CVE-2023-33170: ASP
osv·2023-07-11·CVSS 8.1
CVE-2023-33170 [HIGH] CVE-2023-33170: ASP
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33170https://lists.fedoraproject.org/archives/list/[email protected]/message/EVZVMMCCBBCSCPAW2CRQGOTKIHVFCMRO/https://lists.fedoraproject.org/archives/list/[email protected]/message/O5CFOR6ID2HP45E7ZOGQNX76FPIWP7XR/https://lists.fedoraproject.org/archives/list/[email protected]/message/TLWNIIA2I6YCYVCXYBPBRSZ3UH6KILTG/https://lists.fedoraproject.org/archives/list/[email protected]/message/Y3VJRGNYJXGPF5LXUG3NL45QPK2UU6PL/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33170
2023-07-11
Published