High severity7.4NVD Advisory· Published Feb 26, 2025· Updated Jun 17, 2026
CVE-2024-55581
CVE-2024-55581
Description
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
Affected products
4- cpe:2.3:a:adacore:ada_web_server:25.0:*:*:*:*:*:*:*
- Range: <=25.0.0
Patches
Vulnerability mechanics
References
2- docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdfnvdExploitVendor Advisory
- lists.debian.org/debian-lts-announce/2025/03/msg00007.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.