Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.816556
Categoría:Windows
Título:ASP.NET Core 3.0.x < 3.0.2, 3.1.0 Multiple Vulnerabilities (Jan 2020)
Resumen:ASP.NET Core is prone to multiple vulnerabilities.
Descripción:Summary:
ASP.NET Core is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An error when ASP.NET Core improperly handles web requests.

- An error in ASP.NET Core because it fails to handle objects in memory.

- Multiple errors in .NET because it fails to check the source markup of a file.

Vulnerability Impact:
Successful exploitation will allow an attacker
to run arbitrary code in the context of the current user and conduct DoS attacks.

Affected Software/OS:
ASP.NET Core version 3.0.0, 3.0.1 and 3.1.0

Solution:
Update to ASP.NET Core to 3.0.2 or 3.1.1 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-0602
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
RedHat Security Advisories: RHSA-2020:0130
https://access.redhat.com/errata/RHSA-2020:0130
RedHat Security Advisories: RHSA-2020:0134
https://access.redhat.com/errata/RHSA-2020:0134
Common Vulnerability Exposure (CVE) ID: CVE-2020-0603
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
Common Vulnerability Exposure (CVE) ID: CVE-2020-0605
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0605
Common Vulnerability Exposure (CVE) ID: CVE-2020-0606
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0606
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.