Lucene search

K
cvelistMitreCVELIST:CVE-2024-23771
HistoryJan 22, 2024 - 12:00 a.m.

CVE-2024-23771

2024-01-2200:00:00
mitre
www.cve.org
darkhttpd
authentication
vulnerability
timing side channel
remote attackers

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.9%

darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.9%

Related for CVELIST:CVE-2024-23771