Replay Attack Vulnerability in GoAhead Web Server by Embedthis
CVE-2020-15688

8.8HIGH

Key Information:

Vendor

Embedthis

Status
Vendor
CVE Published:
23 July 2020

What is CVE-2020-15688?

The GoAhead web server prior to version 5.1.2 is susceptible to a replay attack, primarily due to inadequate safeguards in its HTTP Digest Authentication process. In scenarios where TLS is not employed to secure the communication channel, an unauthenticated attacker can capture authentication data and reuse it to bypass security measures, effectively gaining unauthorized access to the system. It is critical for users to implement TLS and upgrade to the latest version to mitigate this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.