Replay Attack Vulnerability in GoAhead Web Server by Embedthis
CVE-2020-15688
8.8HIGH
What is CVE-2020-15688?
The GoAhead web server prior to version 5.1.2 is susceptible to a replay attack, primarily due to inadequate safeguards in its HTTP Digest Authentication process. In scenarios where TLS is not employed to secure the communication channel, an unauthenticated attacker can capture authentication data and reuse it to bypass security measures, effectively gaining unauthorized access to the system. It is critical for users to implement TLS and upgrade to the latest version to mitigate this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved