CVE-2017-11770

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
15/11/2017
Last modified:
20/04/2025

Description

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:aspnetcore:1.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:aspnetcore:1.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:aspnetcore:2.0:*:*:*:*:*:*:*