First published: Wed Feb 26 2025(Updated: )
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ada Web Server | =25.0 | |
Debian Linux | =11.0 | |
Ada Web Server | ||
F5 Traffix Systems Signaling Delivery Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55581 has a high severity due to its potential for man-in-the-middle attacks.
To fix CVE-2024-55581, ensure that your program specifies a proper TLS configuration to enforce certificate verification.
CVE-2024-55581 affects AdaCore Ada Web Server version 25.0.0 when linked with GnuTLS.
CVE-2024-55581 exposes users to man-in-the-middle attacks due to a lack of HTTPS server certificate verification.
CVE-2024-55581 involves AdaCore Ada Web Server and GnuTLS when they are improperly configured.