CVE-2022-34716

MEDIUM

.NET 6.0.0-6.0.7 and .NET Core 3.1-3.1.27 - Authentication Bypass by Spoofing

Title source: llm
STIX 2.1

Description

.NET Spoofing Vulnerability

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0111
EPSS Percentile 78.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (16)
microsoft/.net 6.0.0 - 6.0.8
microsoft/.net_core 3.1 - 3.1.28
microsoft/powershell 7.0 - 7.0.12
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm 3.1.0 - 3.1.28NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 3.1.0 - 3.1.28NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm 3.1.0 - 3.1.28NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 3.1.0 - 3.1.28NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 3.1.0 - 3.1.28NuGet
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 3.1.0 - 3.1.28NuGet
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 6.0.0 - 6.0.8NuGet
... and 6 more
Published Aug 09, 2022
Tracked Since Feb 18, 2026