ASP.NET — CWE-287

All FrameworksASP.NETCWE-287

2 CVEs categorized as CWE-287 — Improper Authentication in ASP.NET.

CVE-2025-24895CRITICAL2025
CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the S…
CVE-2025-24894CRITICAL2025
SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the Servic…