ZeroHour

CVE-2020-15688

PoC
CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description

The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.

Vendors
embedthis
Products
goahead
Weakness
CWE-294
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.