CVE-2023-36873
published 2023-08-08CVE-2023-36873: .NET Framework Spoofing Vulnerability .NET Framework Spoofing Vulnerability
medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
1.33%
67.9th percentile
.NET Framework Spoofing Vulnerability
.NET Framework Spoofing Vulnerability
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_3.5_and_4.6.2 | >= 4.7.0 < 10.0.10240.20107 | 10.0.10240.20107 |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | >= 3.0.0.0 < 10.0.14393.6167 | 10.0.14393.6167 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 3.5.04057.05 | 3.5.04057.05 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 3.5.4654.08 | 3.5.4654.08 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 3.5.09176.01 | 3.5.09176.01 |
| microsoft | microsoft_net_framework_4.6.2 | >= 4.7.0 < 4.7.04057.05 | 4.7.04057.05 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.04057.05 | 4.7.04057.05 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.4654.06 | 4.8.4654.06 |
| msrc | microsoft_net_framework_3.5_and_4.6.2 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.7.2 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.8 | — | — |
| msrc | microsoft_net_framework_3.5_and_4.8.1 | — | — |
| msrc | microsoft_net_framework_4.6.2 | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | — | — |
| msrc | microsoft_net_framework_4.8 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
cvelistv57.4HIGH
vendor_msrc7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Telecontrol Server Basic
cisa_ics·2024-04-11
Siemens Telecontrol Server Basic
ICS Advisory
##
Siemens Telecontrol Server Basic
Release DateApril 11, 2024
Alert CodeICSA-24-102-08
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Telecontrol Server Basic
- Vulnerabilities: Inadequate Encryption Strength, Double Free, Integer Overflow or Wraparound, External Control of File Name or Path, Path Traversal, Improper Input Validation, Missing Encry
Microsoft
.NET Framework Spoofing Vulnerability
vendor_msrc·2023-08-08·CVSS 7.4
CVE-2023-36873 [HIGH] CWE-20 .NET Framework Spoofing Vulnerability
.NET Framework Spoofing Vulnerability
FAQ:
faq
FAQ:
arial
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to create a crafted certificate in order to validate themselves as a trusted source.
.NET Framework: .NET Framework
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028952
Reference: https://support.microsoft.com/help/5028952
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028958
Reference: https://support.microsoft.c
CVEList
.NET Framework Spoofing Vulnerability
cvelistv5·2023-08-08·CVSS 7.4
CVE-2023-36873 [HIGH] CWE-20 .NET Framework Spoofing Vulnerability
.NET Framework Spoofing Vulnerability
.NET Framework Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-08
Published