Lucene search

K
cve[email protected]CVE-2011-3416
HistoryDec 30, 2011 - 1:55 a.m.

CVE-2011-3416

2011-12-3001:55:01
CWE-264
web.nvd.nist.gov
509
asp.net
forms authentication
bypass vulnerability
cve-2011-3416
nvd

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

6 Medium

AI Score

Confidence

Low

0.962 High

EPSS

Percentile

99.5%

The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka “ASP.Net Forms Authentication Bypass Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_7Match-
OR
microsoftwindows_7Match-sp1x64
OR
microsoftwindows_7Match-sp1x86
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008r2x64
OR
microsoftwindows_server_2008sp2itanium
OR
microsoftwindows_server_2008Match-sp2x64
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_server_2008Matchr2itanium
OR
microsoftwindows_vistasp2
OR
microsoftwindows_vistaMatch-sp2
OR
microsoftwindows_xpsp2professional_x64
OR
microsoftwindows_xpMatchsp3unknownenglish

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

6 Medium

AI Score

Confidence

Low

0.962 High

EPSS

Percentile

99.5%