Loading
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.
Use CWE-294, Embedthis vendor hub and Goahead product page to widen CVE-2020-15688 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-41615, CVE-2021-43298 and CVE-2021-42342 for nearby disclosures in the same product family.