CVE-2017-11883 is a denial-of-service vulnerability affecting .NET Core versions 1.0, 1.1, and 2.0, allowing an unauthenticated attacker to remotely disrupt web applications by sending malformed requests. It carries a high CVSS score of 7.5 due to its network-based attack vector and low attack complexity, leading to a complete loss of availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, its high FAUCET Risk Score of 95/100 and community discussion indicate significant concern. Media coverage also confirms its inclusion in a Microsoft Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:microsoft:aspnetcore:1.0:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:microsoft:aspnetcore:1.1:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:microsoft:aspnetcore:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.