Lucene search

K
cve[email protected]CVE-2015-1648
HistoryApr 14, 2015 - 8:59 p.m.

CVE-2015-1648

2015-04-1420:59:10
CWE-19
web.nvd.nist.gov
64
asp.net
microsoft .net framework
information disclosure
cve-2015-1648
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%

ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka “ASP.NET Information Disclosure Vulnerability.”

Affected configurations

NVD
Node
microsoft.net_frameworkMatch1.1sp1
OR
microsoft.net_frameworkMatch2.0sp2
OR
microsoft.net_frameworkMatch3.5
OR
microsoft.net_frameworkMatch3.5.1
OR
microsoft.net_frameworkMatch4.0
OR
microsoft.net_frameworkMatch4.5
OR
microsoft.net_frameworkMatch4.5.1
OR
microsoft.net_frameworkMatch4.5.2

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%