Sustainsys develops SAML2 authentication middleware, a focused library handling single sign-on and federated identity integration across enterprise and cloud applications. The vendor's vulnerability record centers on authentication and cryptographic implementation weaknesses, including capture-replay flaws, name-based authentication bypasses, and improper algorithm implementation that reflect the complexity of SAML protocol state management and validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sustainsys over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41890HIGH Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider.
Prior to versions 1.0.3 and 2.9.2, when a response is | Sep 19, 2023 | 7.5 | 21 | NO | NO |
CVE-2020-5268HIGH In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerability in how tokens are validated in some cases. Saml2 tokens ar | Apr 21, 2020 | 7.3 | 19 | NO | NO |
CVE-2020-5261MEDIUM Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. To | Mar 25, 2020 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sustainsys.
Media articles that mention a CVE ID that affects a product developed by Sustainsys — matched by CVE ID, not by vendor name.