CVE-2018-8171
HIGHASP.NET Core - Security Feature Bypass via Login Attempt Validation
Title source: llmDescription
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1041267
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104659
Patch, Vendor Advisory x_refsource_confirm
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171
Scores
CVSS v3
7.5
EPSS
0.0776
EPSS Percentile
92.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-287
Status
published
Products (6)
microsoft/asp.net_core
1.0
microsoft/asp.net_core
1.1
microsoft/asp.net_core
2.0
microsoft/asp.net_model_view_controller
5.2
microsoft/asp.net_webpages
3.2.3
nuget/Microsoft.AspNetCore.Identity
1.0.0 - 1.0.6NuGet
Published
Jul 11, 2018
Tracked Since
Feb 18, 2026