Zurück zur CVE-Übersicht
CVE-2023-38180
HIGH(7.5)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Risk Signal Score53/100 — HOCH
- CVSS 7.5 — Hoch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
14.0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.5
Technische Schwere
SecBoard-Einordnung
CVE-2023-38180 ist eine Denial-of-Service (DoS)-Schwachstelle, die Microsoft .NET, ASP.NET Core und Visual Studio 2022 betrifft. Ein erfolgreicher Exploit dieser Schwachstelle könnte dazu führen, dass betroffene Anwendungen oder Systeme nicht mehr verfügbar sind. Die Schwachstelle wurde von Microsoft als DoS-Problem identifiziert, was die Verfügbarkeit der Dienste beeinträchtigt.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
.NET and Visual Studio Denial of Service Vulnerability
Erkennung & Indikatoren
Ausnutzung
Aktiv ausgenutzt (CISA KEV).
Behobene Versionen
- dotnet7.0-7.0.110-1.fc38
- dotnet7.0-7.0.110-1.fc37
- .NET SDK 7.0.110
- .NET Runtime 7.0.10
- .NET SDK 6.0.121
- .NET Runtime 6.0.21
Ausgewertete Quellen
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38180
Betroffene Produkte
- cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Referenzen
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproje...
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproje...
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-...