CVE-2023-20572: Medium severity Microsoft ASP vulnerability
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-20572?
CVE-2023-20572 has a medium severity level with a CVSS score of 5.6.
How do I fix CVE-2023-20572?
To mitigate CVE-2023-20572, ensure that your ASP implementation uses secure hash functions and employs measures to prevent timing attacks.
What type of attack is possible due to CVE-2023-20572?
CVE-2023-20572 allows a privileged attacker to perform a brute-force attack against the hash message authentication code.
What could be the consequence of exploiting CVE-2023-20572?
Exploiting CVE-2023-20572 may lead to a loss of data integrity by allowing the input of arbitrary messages.
Which software is affected by CVE-2023-20572?
CVE-2023-20572 affects Microsoft ASP (Microsoft) software.