CVE-2024-55581
published 2025-02-26CVE-2024-55581: When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of…
PriorityP341high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.28%
20.2th percentile
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adacore | ada_web_server | — | — |
| debian | debian_linux | — | — |
| debian | libaws | < libaws 20.2-2+deb11u1 (bullseye) | libaws 20.2-2+deb11u1 (bullseye) |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-55581: libaws - When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour ...
vendor_debian·2024·CVSS 7.4
CVE-2024-55581 [HIGH] CVE-2024-55581: libaws - When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour ...
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Scope: local
bullseye: resolved (fixed in 20.2-2+deb11u1)
GHSA
GHSA-6pc8-5263-hvgq: When AdaCore Ada Web Server 25
ghsa_unreviewed·2025-02-27
CVE-2024-55581 [HIGH] CWE-295 GHSA-6pc8-5263-hvgq: When AdaCore Ada Web Server 25
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
OSV
CVE-2024-55581: When AdaCore Ada Web Server 25
osv·2025-02-26·CVSS 7.4
CVE-2024-55581 [HIGH] CVE-2024-55581: When AdaCore Ada Web Server 25
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-26
Published