CWE-12Variant

ASP.NET Misconfiguration: Missing Custom Error Page

Draft in the CWE catalog · 1 CVE mapped

1
CVEs mapped
What it is

An ASP .NET application must enable custom error pages in order to prevent attackers from mining information from the framework's built-in responses.

Recent examples
none
CVE-2020-6994

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS

⚠️ A crafty HTTP request is all it takes to trigger this buffer overflow in Hirschmann devices! They’re affected by a parsing quirk that lets attackers overflow internal memory - yikes! 🔥 Think of it like a waiter at a restaurant who misreads the menu and delivers an order with double the ingredients, overwhelming the kitchen's capacity. That can lead to chaos behind the scenes! If exploited, an attacker could send specially crafted requests that overflow the device's internal buffer, potentially causing crashes or erratic behavior. This means your critical automation controls might act unpredictably, risking downtime and operational efficiency.

2%
epss
The record
Technical detail
CWE ID
CWE-12
Abstraction
Variant
Structure
Simple
Status
Draft
References (2)