CVE-2021-34532

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

ASP.NET Core and Visual Studio Information Disclosure Vulnerability

References

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34532

Details

Source: MITRE

Published: 2021-08-12

Updated: 2021-08-18

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* versions from 2.1 to 2.1.2 (inclusive)

cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* versions from 3.1 to 3.1.17 (inclusive)

cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* versions from 5.0 to 5.0.8 (inclusive)

cpe:2.3:a:microsoft:visual_studio_2019:8.10:*:*:*:*:macos:*:*

cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* versions from 16.0 to 16.10 (inclusive)

Tenable Plugins

View all (11 total)

IDNameProductFamilySeverity
152605RHEL 7 : .NET Core 3.1 on RHEL 7 (RHSA-2021:3143)NessusRed Hat Local Security Checks
medium
152604RHEL 8 : .NET 5.0 (RHSA-2021:3148)NessusRed Hat Local Security Checks
medium
152595RHEL 8 : .NET Core 3.1 (RHSA-2021:3142)NessusRed Hat Local Security Checks
medium
152592RHEL 7 : .NET 5.0 on RHEL 7 (RHSA-2021:3147)NessusRed Hat Local Security Checks
medium
152591CentOS 8 : .NET Core 3.1 (CESA-2021:3142)NessusCentOS Local Security Checks
medium
152582CentOS 8 : .NET 5.0 (CESA-2021:3148)NessusCentOS Local Security Checks
medium
152549Oracle Linux 8 : .NET / Core / 3.1 (ELSA-2021-3142)NessusOracle Linux Local Security Checks
medium
152548Oracle Linux 8 : .NET / 5.0 (ELSA-2021-3148)NessusOracle Linux Local Security Checks
medium
152528Security Update for Microsoft ASP.NET Core (August 2021)NessusWindows
medium
152482Security Update for Visual Studio 2019 (August 2021) (macOS)NessusMacOS X Local Security Checks
medium
152423Security Updates for Microsoft Visual Studio Products (August 2021)NessusWindows : Microsoft Bulletins
medium