CVE-2020-0603 is a remote code execution vulnerability in ASP.NET Core that arises from improper memory handling, allowing an attacker to execute arbitrary code in the context of the current user. This vulnerability affects various Microsoft and Red Hat ASP.NET Core and Enterprise Linux products. With a CVSS score of 8.8 (HIGH), it has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Despite its high severity and FAUCET Risk Score of 85/100, there is no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:3.0:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:3.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.