CVE-2010-3332
6.4
CVSS Score
Medium
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N
Link copied!
Description
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
None
Affected Software Configurations
- a microsoft .net_framework 1.1 sp1 * * * * * *
- a microsoft .net_framework 2.0 sp1 * * * * * *
- a microsoft .net_framework 2.0 sp2 * * * * * *
- a microsoft .net_framework 3.5 - * * * * * *
- a microsoft .net_framework 3.5 sp1 * * * * * *
- a microsoft .net_framework 3.5.1 * * * * * * *
- a microsoft .net_framework 4.0 - * * * * * *
- a microsoft internet_information_services - * * * * * * *
Weaknesses (CWE)
- CWE-209
References & External Links
- http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx
- http://isc.sans.edu/diary.html?storyid=9568
- http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/
- http://secunia.com/advisories/41409
- http://securitytracker.com/id?1024459
- http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310
- http://twitter.com/thaidn/statuses/24832350146
- http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx
- http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx
- http://www.ekoparty.org/juliano-rizzo-2010.php
- http://www.microsoft.com/technet/security/advisory/2416728.mspx
- http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle
- http://www.securityfocus.com/bid/43316
- http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security
- http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html
- http://www.vupen.com/english/advisories/2010/2429
- http://www.vupen.com/english/advisories/2010/2751
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61898
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365
- http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx
- http://isc.sans.edu/diary.html?storyid=9568
- http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/
- http://secunia.com/advisories/41409
- http://securitytracker.com/id?1024459
- http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310
- http://twitter.com/thaidn/statuses/24832350146
- http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx
- http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx
- http://www.ekoparty.org/juliano-rizzo-2010.php
- http://www.microsoft.com/technet/security/advisory/2416728.mspx
- http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle
- http://www.securityfocus.com/bid/43316
- http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security
- http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html
- http://www.vupen.com/english/advisories/2010/2429
- http://www.vupen.com/english/advisories/2010/2751
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61898
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365
External Resources
CVE History Timeline
Sep 22, 2010 22:31
Initial Analysis
Aug 17, 2017 01:32
CVE Modified
Sep 19, 2017 01:31
CVE Modified
Oct 12, 2018 21:58
CVE Modified
Nov 23, 2020 19:50
Modified Analysis
May 14, 2024 02:21
CVE Modified
Nov 21, 2024 01:18
CVE Modified