CVE-2017-15883

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
progresssitefinity
5.1
progresssitefinity
5.2
progresssitefinity
5.3
progresssitefinity
5.4
progresssitefinity
6.0
progresssitefinity
6.1
progresssitefinity
6.2
progresssitefinity
6.3
progresssitefinity
7.0
progresssitefinity
7.1
progresssitefinity
7.2
progresssitefinity
7.3
progresssitefinity
8.0
progresssitefinity
8.1
progresssitefinity
8.2
progresssitefinity
9.0
progresssitefinity
9.1
progresssitefinity
9.2
progresssitefinity
10.0
progresssitefinity
10.1
𝑥
= Vulnerable software versions