CVE-2018-8171

HIGH

ASP.NET Core - Security Feature Bypass via Login Attempt Validation

Title source: llm
STIX 2.1

Description

A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041267
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104659

Scores

CVSS v3 7.5
EPSS 0.0776
EPSS Percentile 92.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287
Status published
Products (6)
microsoft/asp.net_core 1.0
microsoft/asp.net_core 1.1
microsoft/asp.net_core 2.0
microsoft/asp.net_model_view_controller 5.2
microsoft/asp.net_webpages 3.2.3
nuget/Microsoft.AspNetCore.Identity 1.0.0 - 1.0.6NuGet
Published Jul 11, 2018
Tracked Since Feb 18, 2026