6.8
CVSSv2

CVE-2020-15688

Published: 23/07/2020 Updated: 31/01/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The HTTP Digest Authentication in the GoAhead web server prior to 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote malicious user to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

embedthis goahead

Exploits

A security vulnerability affecting GoAhead versions 2 to 5 has been identified when using Digest authentication over HTTP The HTTP Digest Authentication in the GoAhead web server does not completely protect against replay attacks This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to prote ...