Severity
9.8CRITICAL
EPSS
3.6%
top 12.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateFeb 13

Description

NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages30 packages

Patches

🔴Vulnerability Details

5
GHSA
NuGet Client Security Feature Bypass Vulnerability2024-02-13
OSV
NuGet Client Security Feature Bypass Vulnerability2024-02-13
OSV
dotnet6, dotnet7, dotnet8 vulnerabilities2024-01-11
OSV
CVE-2024-0057: NET,2024-01-09
CVEList
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability2024-01-09

📋Vendor Advisories

3
Ubuntu
.NET vulnerabilities2024-01-11
Microsoft
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability2024-01-09
Red Hat
dotnet: X509 Certificates - Validation Bypass across Azure2024-01-09

🕵️Threat Intelligence

1
Trendmicro
The January 2024 Security Update Review2024-01-09