CVE-2024-55581

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Configurations

Configuration 1 (hide)

cpe:2.3:a:adacore:ada_web_server:25.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

07 Apr 2025, 18:39

Type Values Removed Values Added
References () https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf - () https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf - Exploit, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2025/03/msg00007.html - () https://lists.debian.org/debian-lts-announce/2025/03/msg00007.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:adacore:ada_web_server:25.0:*:*:*:*:*:*:*
First Time Adacore ada Web Server
Adacore
Debian debian Linux
Debian

10 Mar 2025, 20:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/03/msg00007.html -

04 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
CWE CWE-295
References () https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf - () https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf -
Summary
  • (es) Cuando AdaCore Ada Web Server 25.0.0 está vinculado con GnuTLS, el comportamiento predeterminado de AWS.Client es vulnerable a un ataque de intermediario debido a la falta de verificación del certificado de un servidor HTTPS (a menos que el programa que lo utiliza especifique una configuración TLS).

26 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 22:15

Updated : 2025-04-07 18:39


NVD link : CVE-2024-55581

Mitre link : CVE-2024-55581

CVE.ORG link : CVE-2024-55581


JSON object : View

Products Affected

adacore

  • ada_web_server

debian

  • debian_linux
CWE
CWE-295

Improper Certificate Validation