Impact
Apache HTTP Server’s mod_auth_digest module contains a missing authentication check that allows an unauthenticated remote client to forge Authorization headers. When Digest authentication is enabled with AuthDigestNcCheck, the forged request forces the server to repeatedly challenge for credentials, consuming processing resources and interrupting service. The primary consequence is a denial‑of‑service, affecting the availability of web services hosted on the vulnerable server.
Affected Systems
The issue impacts all installations of Apache HTTP Server version 2.4.68 and earlier on any platform. The affected component is mod_auth_digest when Digest authentication is enabled.
Risk and Exploitability
The vulnerability can be triggered by any remote host without credentials, requiring only crafted HTTP requests. No authentication or privileged access is needed, making it straightforward to exploit. Exploitation leads to service interruption for all clients served by the affected instance. With a CVSS score of 7.5, the vulnerability is considered High severity. Although EPSS is not available and KEV is not listed in the CISA KEV catalog, the ease of exploitation and impact on availability justify immediate attention.
OpenCVE Enrichment