CVE-2021-35235CWE-11

ASP.NET Debug Feature Enabled

Medium · published October 27, 2021

CVSS v3.1
5.3
EPSS
1%
Percentile
68.0
In the wild
Unconfirmed
What it is

The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the execution of an application. If an attacker could successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in targeting SWI with malicious intent.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.01276 · 68.0th percentile
Weakness
CWE-11 · ASP.NET Misconfiguration: Creating Debug Binary
Published
2021-10-27T00:55Z
EPSS history
Timeline
  • 27 OCT 00:55Z
    ASP.NET Debug Feature Enabled
    cvelistv5