ASP.NET DEBUG Method Enabled

medium Web App Scanning Plugin ID 112353

Synopsis

ASP.NET DEBUG Method Enabled

Description

It is possible to send debug statements to the remote ASP scripts via the http DEBUG method. A remote, unauthenticated attacker may leverage this to alter the runtime of the remote scripts.

Solution

Make sure that DEBUG statements are disabled or only usable by authenticated users.

See Also

https://support.microsoft.com/en-us/help/815157/how-to-disable-debugging-for-asp-net-applications

Plugin Details

Severity: Medium

ID: 112353

Type: remote

Published: 8/29/2018

Updated: 9/7/2021

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:microsoft:asp.net:-:*:*:*:*:*:*:*

Exploit Available: true

Reference Information