HIGH
Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."
Published May 15, 2013
7.5
HIGHCVSS 2.0
EPSS 20.63%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.