Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47995
HistoryJul 10, 2024 - 6:04 a.m.

Denial Of Service (DoS)

2024-07-1006:04:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
denial of service
.net
cpu consumption
x.509 certificate

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

27.4%

.NET is vulnerable to Denial of Service (DoS). The vulnerability is due to excessive CPU consumption caused by parsing a malicious X.509 certificate or collection of certificates. An attacker can exploit this by providing a specially crafted certificate that triggers high CPU usage, resulting in Denial of Service (DoS).

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

27.4%