Show plain JSON{"id": "CVE-2013-1337", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2013-05-15T03:36:34.420", "references": [{"url": "http://www.us-cert.gov/ncas/alerts/TA13-134A", "tags": ["Third Party Advisory", "US Government Resource"], "source": "secure@microsoft.com"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-040", "source": "secure@microsoft.com"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16741", "source": "secure@microsoft.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-287"}]}], "descriptions": [{"lang": "en", "value": "Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka \"Authentication Bypass Vulnerability.\""}, {"lang": "es", "value": "Microsoft .NET Framework v4.5 no crea correctamente los requisitos de la pol\u00edtica de Windows Communication Foundation (WCF) como punto final de autenticaci\u00f3n en ciertas situaciones relacionadas con las contrase\u00f1as a trav\u00e9s de HTTPS, lo que permite a atacantes remotos evitar la autenticaci\u00f3n mediante el env\u00edo de peticiones al punto final de autenticaci\u00f3n, tambi\u00e9n conocido como \"Authentication Bypass Vulnerability.\""}], "lastModified": "2018-10-12T22:04:19.757", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:.net_framework:4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61FAD9EE-FA7F-4B39-8A9B-AFFAEC8BF214"}], "operator": "OR"}]}], "sourceIdentifier": "secure@microsoft.com"}