Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/mono.Upgrade dev-util/mono-debugger. | Oct 30, 2017 | Sep 22, 2010 |
| Suse | — | Upgrade mono-jscriptUpgrade mono-wcfUpgrade mono-data-sybaseUpgrade mono-coreUpgrade mono-data-oracleUpgrade monodoc-coreUpgrade bytefx-data-mysqlUpgrade mono-locale-extrasUpgrade mono-data-postgresqlUpgrade mono-dataUpgrade mono-winfxcoreUpgrade mono-webUpgrade mono-extrasUpgrade mono-data-sqliteUpgrade mono-develUpgrade mono-winformsUpgrade mono-nunitUpgrade mono-data-firebird | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub