Vulnerability Details CVE-2017-11770
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.13
EPSS Ranking 93.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-11770
-
cpe:2.3:a:microsoft:aspnetcore:1.0
-
cpe:2.3:a:microsoft:aspnetcore:1.1
-
cpe:2.3:a:microsoft:aspnetcore:2.0