CVE-2025-55248

Public on 2025-10-14
Modified on 2025-10-16
Description
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
8.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 dotnet6.0 No Fix Planned
Amazon Linux 2023 dotnet8.0 2025-10-23 ALAS2023-2025-1230 Fixed
Amazon Linux 2023 dotnet9.0 2025-10-23 ALAS2023-2025-1231 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
NVD CVSSv3 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N