An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.

Project Subscriptions

Vendors Products
Adacore Subscribe
Ada Web Services Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adacore
Adacore ada Web Services
Weaknesses CWE-297
CPEs cpe:2.3:a:adacore:ada_web_services:20.00:*:*:*:*:*:*:*
Vendors & Products Adacore
Adacore ada Web Services
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 17:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-13T18:25:46.690Z

Reserved: 2024-05-30T00:00:00

Link: CVE-2024-37015

cve-icon Vulnrichment

Updated: 2024-08-13T18:21:01.840Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T17:15:23.553

Modified: 2024-08-14T02:07:05.410

Link: CVE-2024-37015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses