CVE-2023-38178
published 2023-08-08CVE-2023-38178: .NET Core and Visual Studio Denial of Service Vulnerability
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.56%
83.4th percentile
.NET Core and Visual Studio Denial of Service Vulnerability
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm64 | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x86 | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 7.0.0 < 7.0.10 | 7.0.10 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.18 | 17.2.18 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.10 | 17.4.10 |
| microsoft | net | — | — |
| microsoft | net_6.0 | >= 6.0.0 < 6.0.21 | 6.0.21 |
| microsoft | visual_studio_2022 | >= 17.2.0 < 17.2.18 | 17.2.18 |
| microsoft | visual_studio_2022 | >= 17.4.0 < 17.4.10 | 17.4.10 |
| msrc | microsoft_visual_studio_2022_version_17.2 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.4 | — | — |
| msrc | net_6.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens ST7 ScadaConnect
cisa_ics·2024-06-13·CVSS 7.5
[HIGH] Siemens ST7 ScadaConnect
ICS Advisory
##
Siemens ST7 ScadaConnect
Release DateJune 13, 2024
Alert CodeICSA-24-165-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: ST7 ScadaConnect
- Vulnerabilities: Integer Overflow or Wraparound, Double Free, Improper Certificate Validation, Inefficient Regular Ex
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2023-08-10·CVSS 7.8
CVE-2023-38180 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
USN-6278-1 fixed several vulnerabilities in .NET. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that .NET did properly handle the execution of
certain commands. An attacker could possibly use this issue to
achieve remote code execution. (CVE-2023-35390)
Benoit Foucher discovered that .NET did not properly implement the
QUIC stream limit in HTTP/3. An attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38178)
It was discovered that .NET did not properly handle the disconnection
of potentially malicious clients interfacing with a Kestrel server. An
attacker could possibly use this issue to cause a denial of servi
Microsoft
.NET Core and Visual Studio Denial of Service Vulnerability
vendor_msrc·2023-08-08·CVSS 7.5
CVE-2023-38178 [HIGH] CWE-400 .NET Core and Visual Studio Denial of Service Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
.NET Core: .NET Core
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://dotnet.microsoft.com/download/dotnet/6.0
Reference: https://support.microsoft.com/help/5029688
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.2
Reference: https://docs.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.4
Reference: https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2023-08-08·CVSS 7.8
CVE-2023-38180 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that .NET did not properly handle the execution
of certain commands. An attacker could possibly use this issue to
achieve remote code execution. (CVE-2023-35390)
Benoit Foucher discovered that .NET did not properly implement the
QUIC stream limit in HTTP/3. An attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38178)
It was discovered that .NET did not properly handle the disconnection
of potentially malicious clients interfacing with a Kestrel server. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-38180)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: ASP.NET Kestrel stream flow control leads to Denial of Service
vendor_redhat·2023-08-08·CVSS 7.5
CVE-2023-38178 [HIGH] CWE-400 dotnet: ASP.NET Kestrel stream flow control leads to Denial of Service
dotnet: ASP.NET Kestrel stream flow control leads to Denial of Service
.NET Core and Visual Studio Denial of Service Vulnerability
A vulnerability was found in dotNET in Kestrel component. This issue may allow a malicious client to bypass the QUIC stream limit in both ASP.NET and .NET runtimes in HTTP/3, resulting in a denial of service.
Statement: QUIC support is unavailable in the .NET configuration that Red Hat ships. Hence, none of the Red Hat software are affected.
Package: rh-dotnet60 (.NET 6.0 on Red Hat Enterprise Linux) - Not affected
Package: dotnet6.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet7.0 (Red Hat Enterprise Linux 8) - Not affected
Package: dotnet6.0 (Red Hat Enterprise Linux 9) - Not affected
Package: dotnet7.0 (Red Hat Enterprise Linux 9) - Not
OSV
dotnet6, dotnet7 vulnerabilities
osv·2023-08-10·CVSS 7.8
CVE-2023-35390 [HIGH] dotnet6, dotnet7 vulnerabilities
dotnet6, dotnet7 vulnerabilities
USN-6278-1 fixed several vulnerabilities in .NET. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that .NET did properly handle the execution of
certain commands. An attacker could possibly use this issue to
achieve remote code execution. (CVE-2023-35390)
Benoit Foucher discovered that .NET did not properly implement the
QUIC stream limit in HTTP/3. An attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38178)
It was discovered that .NET did not properly handle the disconnection
of potentially malicious clients interfacing with a Kestrel server. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-38180)
OSV
.NET Denial of Service Vulnerability
osv·2023-08-09·CVSS 7.5
CVE-2023-38178 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2023-38178: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET Kestrel where a malicious client can bypass QUIC stream limit in HTTP/3 in both ASP.NET and .NET runtimes resulting in denial of service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/268
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected software
* Any .NET 7.0 applicat
GHSA
.NET Denial of Service Vulnerability
ghsa·2023-08-09·CVSS 7.5
CVE-2023-38178 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2023-38178: .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 7.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET Kestrel where a malicious client can bypass QUIC stream limit in HTTP/3 in both ASP.NET and .NET runtimes resulting in denial of service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/268
### Mitigation factors
Microsoft has not identified any mitigating factors for this vulnerability.
## Affected software
* Any .NET 7.0 applicat
OSV
CVE-2023-38178
osv·2023-08-08·CVSS 7.5
CVE-2023-38178 [HIGH] CVE-2023-38178
.NET Core and Visual Studio Denial of Service Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-08
Published