CVE-2023-38180 is a Denial of Service vulnerability impacting Microsoft .NET, ASP.NET Core, and Visual Studio products, including Fedora Project distributions. With a CVSS score of 7.5 (High), this network-exploitable vulnerability requires no user interaction and can lead to a complete denial of service. It is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.0.21CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.10CPE matchmatch criteria | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | ||
>= 2.1, < 2.1.40CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* | ||
>= 17.2.0, < 17.2.18CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* | ||
>= 17.4.0, < 17.4.10CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
.NET Denial of Service Vulnerability
Aug 9, 2023.NET and Visual Studio Denial of Service Vulnerability
Aug 8, 2023dotnet: Kestrel vulnerability to slow read attacks leading to Denial of Service attack
Aug 8, 2023