A vulnerability was found in Microsoft .NET 3.1/5.0. It has been classified as problematic. Affected is an unknown code block. Applying a patch is able to eliminate this problem. A possible mitigation has been published immediately after the disclosure of the vulnerability.
Description
A denial of service vulnerability exists when ASP.NET Core improperly handles client disconnect.
Affected software
- Any .NET 5.0 application running on .NET 5.0.6 or lower
- Any .NET Core 3.1 application running on .NET Core 3.1.15 or lower
Common Vulnerability Scoring System Score Details
- CVSS v3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v3 Base Score: 5.9
- Attack Vector: Network
- Attack Complexity: High
- Availability Impact: High