Introduction

EVS is actively responding to the reported vulnerability in ASP .NET. We are currently conducting a product-by-product analysis to determine if any are potentially impacted by the vulnerability. This is an ongoing investigation, so please check this bulletin page frequently for updates.

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

An attacker who successfully exploited this vulnerability could view sensitive information such as other user's credentials (Confidentiality) and make changes to file contents on the target server (Integrity), and they might be able to force a crash within the server (Availability).

 

Products under investigation 

ProductVersionStatusComment
CerebrumAllNot vulnerable 
IPDirectorAllUnder analysis 
IPWeb API ServicesAllUnder analysis 
XPloreAllUnder analysis 
XedioAllUnder analysis 
C-CastAllUnder analysis 
MADAllUnder analysis 
XTAccessAllUnder analysis 
XViewerAllUnder analysis 
XSquareAll Under analysis 
XFile3AllUnder analysis 
XNetMonitor / XNetWebMonitorAllUnder analysis 
Move I/O / Move UPAllUnder analysis 
C-NEXTAllUnder analysis 
Ingest FunnelAllUnder analysis 
MultiReviewAllUnder analysis 
Truck ManagerAllUnder analysis 

 

Linux Products

ProductVersionStatusComments
NeuronAllNot vulnerable 
SynapseAllUnder analysis 
VIA MAPAllUnder analysis 
IPWeb Streaming ServerAllUnder analysis 
MediaHubAllUnder analysis 
XT / MulticamAllUnder analysis 
XHub-VIAAllUnder analysis 
XS-NEOAllUnder analysis 
XR-NEOAllUnder analysis 
XeebraAllUnder analysis 
LSGAllUnder analysis 
LSM-VIAAllUnder analysis 
XtraMotionAllUnder analysis 
DYVI EOL 
Ingest Funnel EOL 

This list is under investigation and will be regularly updated.

Please contact the EVS support team to have more information.

More information

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55315

https://github.com/dotnet/aspnetcore/issues/64033

https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-october-2025-servicing-updates/ 

https://www.nuget.org/packages/Microsoft.AspNetCore.Server.Kestrel.Core