cbcvebase.
CVE-2024-55581
published 2025-02-26

CVE-2024-55581: When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of…

PriorityP341high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.28%
20.2th percentile
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).

Affected

3 ranges
VendorProductVersion rangeFixed in
adacoreada_web_server
debiandebian_linux
debianlibaws< libaws 20.2-2+deb11u1 (bullseye)libaws 20.2-2+deb11u1 (bullseye)

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.