CVE-2020-15688
PoC —CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.
- Vendors
- embedthis
- Products
- goahead
- Weakness
- CWE-294
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.