A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041267 | third party advisory vdb entry |
http://www.securityfocus.com/bid/104659 | third party advisory vdb entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8171 | patch vendor advisory |