CVE-2023-38180
HIGH7.5⚠ KEVEPSS 0.88%.NET and Visual Studio Denial of Service Vulnerability
Published: 8/9/2023Modified: 10/22/2025Added to CISA KEV: 8/9/2023
Also known as:GHSA-vmch-3w2x-vhgqBIT-aspnet-core-2023-38180BIT-dotnet-2023-38180BIT-dotnet-sdk-2023-38180
Description
.NET and Visual Studio Denial of Service Vulnerability
Affected packages (8)
- Bitnami/aspnet-core>= 2.1.0, < 2.1.40
- Bitnami/dotnet>= 6.0.0, < 6.0.21, >= 7.0.0, < 7.0.10
- Bitnami/dotnet-sdk>= 6.0.0, < 6.0.21, >= 7.0.0, < 7.0.10
- NuGet/Microsoft.AspNetCore.App.Runtime.win-arm64>= 7.0.0, < 7.0.10
- NuGet/Microsoft.AspNetCore.App.Runtime.win-x64>= 7.0.0, < 7.0.10
- NuGet/Microsoft.AspNetCore.App.Runtime.win-x86>= 7.0.0, < 7.0.10
- NuGet/Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv>= 6.0.0, < 6.0.21
- NuGet/Microsoft.AspNetCore.Server.Kestrel.Transport.Socketsfrom 0, < 2.1.40
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H |
References (10)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-38180
- PATCHhttps://github.com/dotnet/runtime
- WEBhttps://github.com/dotnet/runtime/issues/90170
- WEBhttps://github.com/dotnet/runtime/security/advisories/GHSA-vmch-3w2x-vhgq
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY/
- WEBhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
- WEBhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38180