CVE-2017-9248: Progress ASP.NET AJAX and Sitefinity
EPSS75.0%No. 674 of 1739 in KEV
CVE year2017~4 yrs before listing
Same vendor in KEV9
Same product1
| Field | Value |
|---|---|
| Vendor | Progress |
| Product | ASP.NET AJAX and Sitefinity |
| Name | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability |
| Added to KEV | 2021-11-03 |
| US federal due date | 2022-05-03 |
| Ransomware use | Unknown |
| CWE | CWE-522 |
CISA description
Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Progress ASP.NET AJAX and Sitefinity vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.