CVE-2017-15883: Weak Encryption
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15883?
CVE-2017-15883 is a cryptographic vulnerability in Sitefinity versions 5.1 to 10.1 that allows remote attackers to bypass authentication or gain privileges.
Which versions of Sitefinity are affected by CVE-2017-15883?
Sitefinity versions 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x are affected by CVE-2017-15883.
What is the severity of CVE-2017-15883?
CVE-2017-15883 has a severity score of 9.8 (Critical).
How can remote attackers exploit CVE-2017-15883?
Remote attackers can exploit CVE-2017-15883 to bypass authentication and cause a denial of service on load balanced sites or gain privileges.
Where can I find more information about CVE-2017-15883?
You can find more information about CVE-2017-15883 at the following references: [1], [2].