CVE-2010-3332 is a padding oracle vulnerability affecting Microsoft .NET Framework versions 1.1 through 4.0, specifically when used with ASP.NET in IIS. This flaw allows remote attackers to decrypt and modify encrypted View State data, potentially leading to forged cookies or unauthorized file access. With a CVSS score of 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N) and an EPSS score of 0.743, it indicates a high likelihood of exploitation with low attack complexity and significant impact on confidentiality and integrity. While not on the KEV catalog, multiple public exploits exist on ExploitDB, demonstrating its exploitability. Despite its age and exploit availability, community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.