Replay Attack Vulnerability in GoAhead Web Server by Embedthis
CVE-2020-15688
8.8HIGH
What is CVE-2020-15688?
The GoAhead web server prior to version 5.1.2 is susceptible to a replay attack, primarily due to inadequate safeguards in its HTTP Digest Authentication process. In scenarios where TLS is not employed to secure the communication channel, an unauthenticated attacker can capture authentication data and reuse it to bypass security measures, effectively gaining unauthorized access to the system. It is critical for users to implement TLS and upgrade to the latest version to mitigate this vulnerability.