CVE-2020-15688
23.07.2020, 13:15
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.Enginsight
Vendor | Product | Version |
---|---|---|
embedthis | goahead | 𝑥 < 5.1.2 |
𝑥
= Vulnerable software versions
References