CVE-2023-36799
published 2023-09-12CVE-2023-36799: .NET Core and Visual Studio Denial of Service Vulnerability
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
4.66%
90.7th percentile
.NET Core and Visual Studio Denial of Service Vulnerability
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 6.0.0 < 6.0.22 | 6.0.22 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 7.0.0 < 7.0.11 | 7.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 6.0.0 < 6.0.22 | 6.0.22 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 7.0.0 < 7.0.11 | 7.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 6.0.0 < 6.0.22 | 6.0.22 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 7.0.0 < 7.0.11 | 7.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 6.0.0 < 6.0.22 | 6.0.22 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 7.0.0 < 7.0.11 | 7.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 6.0.0 < 6.0.22 | 6.0.22 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 7.0.0 < 7.0.11 | 7.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 6.0.0 < 6.0.22 | 6.0.22 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 7.0.0 < 7.0.11 | 7.0.11 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.21 | 17.2.21 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.13 | 17.4.13 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.9 | 17.6.9 |
| microsoft | microsoft_visual_studio_2022_version_17.7 | >= 17.7.0 < 17.6.9 | 17.6.9 |
| microsoft | net | — | — |
| microsoft | net | — | — |
| microsoft | net_6.0 | >= 6.0.0 < 6.0.24 | 6.0.24 |
| microsoft | net_7.0 | >= 7.0.0 < 7.0.13 | 7.0.13 |
| microsoft | powershell_7.2 | >= 7.2.0 < 7.2.14 | 7.2.14 |
| microsoft | powershell_7.3 | >= 7.3.0 < 7.2.14 | 7.2.14 |
| microsoft | visual_studio_2022 | >= 17.2 < 17.2.19 | 17.2.19 |
| microsoft | visual_studio_2022 | >= 17.4 < 17.4.11 | 17.4.11 |
| microsoft | visual_studio_2022 | >= 17.6 < 17.6.7 | 17.6.7 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
.Net regressions
osv·2023-10-25·CVSS 6.5
CVE-2023-36799 [MEDIUM] .Net regressions
.Net regressions
USN-6438-1 fixed vulnerabilities in .Net. It was discovered that the fix
for [CVE-2023-36799](https://ubuntu.com/security/CVE-2023-36799) was incomplete. This update fixes the problem.
Original advisory details:
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service. (CVE-2023-36799)
It was discovered that the .NET Kestrel web server did not properly
handle HTTP/2 requests. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-44487)
OSV
.Net regressions
osv·2023-10-25·CVSS 6.5
CVE-2023-36799 [MEDIUM] .Net regressions
.Net regressions
USN-6362-1 fixed vulnerabilities in .Net. It was discovered that the fix
for [CVE-2023-36799](https://ubuntu.com/security/CVE-2023-36799) was incomplete. This update fixes the problem.
Original advisory details:
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service.
OSV
dotnet6, dotnet7 vulnerabilities
osv·2023-10-19·CVSS 6.5
CVE-2023-36799 [MEDIUM] dotnet6, dotnet7 vulnerabilities
dotnet6, dotnet7 vulnerabilities
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service. (CVE-2023-36799)
It was discovered that the .NET Kestrel web server did not properly
handle HTTP/2 requests. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-44487)
OSV
Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
osv·2023-09-12·CVSS 6.5
CVE-2023-36799 [MEDIUM] Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET where reading a maliciously crafted X.509 certificate may result in Denial of Service. This issue only affects Linux systems.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/275
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
OSV
CVE-2023-36799
osv·2023-09-12·CVSS 6.5
CVE-2023-36799 [MEDIUM] CVE-2023-36799
.NET Core and Visual Studio Denial of Service Vulnerability
GHSA
Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
ghsa·2023-09-12·CVSS 6.5
CVE-2023-36799 [MEDIUM] CWE-400 Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2023-36799: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET where reading a maliciously crafted X.509 certificate may result in Denial of Service. This issue only affects Linux systems.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/275
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
CISA ICS
Siemens ST7 ScadaConnect
cisa_ics·2024-06-13·CVSS 7.5
[HIGH] Siemens ST7 ScadaConnect
ICS Advisory
##
Siemens ST7 ScadaConnect
Release DateJune 13, 2024
Alert CodeICSA-24-165-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: ST7 ScadaConnect
- Vulnerabilities: Integer Overflow or Wraparound, Double Free, Improper Certificate Validation, Inefficient Regular Ex
Ubuntu
.Net regressions
vendor_ubuntu·2023-10-25·CVSS 6.5
CVE-2023-36799 [MEDIUM] .Net regressions
Title: .Net regressions
Summary: An incomplete fix was discovered in .Net.
USN-6438-1 fixed vulnerabilities in .Net. It was discovered that the fix
for [CVE-2023-36799](https://ubuntu.com/security/CVE-2023-36799) was incomplete. This update fixes the problem.
Original advisory details:
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service. (CVE-2023-36799)
It was discovered that the .NET Kestrel web server did not properly
handle HTTP/2 requests. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-44487)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
.Net regressions
vendor_ubuntu·2023-10-25·CVSS 6.5
CVE-2023-36799 [MEDIUM] .Net regressions
Title: .Net regressions
Summary: An incomplete fix was discovered in .Net.
USN-6362-1 fixed vulnerabilities in .Net. It was discovered that the fix
for [CVE-2023-36799](https://ubuntu.com/security/CVE-2023-36799) was incomplete. This update fixes the problem.
Original advisory details:
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2023-10-19·CVSS 6.5
CVE-2023-36799 [MEDIUM] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in dotnet6, dotnet7.
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service. (CVE-2023-36799)
It was discovered that the .NET Kestrel web server did not properly
handle HTTP/2 requests. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-44487)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: Denial of Service with Client Certificates using .NET Kestrel
vendor_redhat·2023-09-13·CVSS 6.5
CVE-2023-36799 [MEDIUM] CWE-400 dotnet: Denial of Service with Client Certificates using .NET Kestrel
dotnet: Denial of Service with Client Certificates using .NET Kestrel
.NET Core and Visual Studio Denial of Service Vulnerability
A vulnerability was found in dotnet. This issue can lead to a denial of service when processing X.509 certificates.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: rh-dotnet60 (.NET 6.0 on Red Hat Enterprise Linux) - Not affected
Ubuntu
.NET vulnerability
vendor_ubuntu·2023-09-12
CVE-2023-36799 .NET vulnerability
Title: .NET vulnerability
Summary: .NET could be made to crash if it received a specially crafted request.
Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
.NET Core and Visual Studio Denial of Service Vulnerability
vendor_msrc·2023-09-12·CVSS 6.5
CVE-2023-36799 [MEDIUM] CWE-400 .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send the user a malicious request and convince them to open it.
.NET Core & Visual Studio: .NET Core & Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://dotnet.microsoft.com/download/dotnet/6.0
Reference: https://support.microsoft.com/help/5032874
Reference: https://dotnet.microsoft.com/en-us/download/dotnet/7.0
Reference: https://support.microsoft.com/help/5032875
Remediation: Release Notes
Reference: https://my.visualstudio.com/D
No detection rules found.
No public exploits indexed.
2023-09-12
Published