CVE-2024-55581
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Feb 26, 2025
Updated: Mar 10, 2025
CWE ID 295
Summary
CVE-2024-55581: AdaCore Ada Web Server 25.0.0, when integrated with GnuTLS, is susceptible to man-in-the-middle attacks due to the default configuration of AWS.Client. This vulnerability arises from the absence of verification for the HTTPS server's certificate. To mitigate this risk, developers must explicitly provide a TLS configuration within their using program.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ada Web Server