9.8
CVSSv3

CVE-2024-23771

Published: 22/01/2024 Updated: 26/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

darkhttpd prior to 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote malicious users to bypass authentication via a timing side channel.

Vulnerable Product Search on Vulmon Subscribe to Product

unix4lyfe darkhttpd

Mailing Lists

On Tue, Jan 23, 2024 at 11:39:19AM +0100, Matthias Gerstner wrote: Mitre assigned the CVEs by now as follows: CVE-2024-23771 CVE-2024-23770 Cheers Matthias ...