VYPR
High severity8.8NVD Advisory· Published Jul 23, 2020· Updated Jun 17, 2026

CVE-2020-15688

CVE-2020-15688

Description

The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Embedthis/Goahead2 versions
    cpe:2.3:a:embedthis:goahead:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:embedthis:goahead:*:*:*:*:*:*:*:*range: <5.1.2
    • (no CPE)range: <5.1.2
  • GoAhead/GoAhead web serverdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.