Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45206
HistoryJan 30, 2024 - 4:42 p.m.

Timing Side-Channel Attack

2024-01-3016:42:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
darkhttpd
vulnerability
timing side-channel
attack
remote
authentication

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.9%

darkhttpd is vulnerable of Timing Side-Channel Attack. The vulnerability due to strcmp is not implemented in constant time. it allows a remote attacker may exploit timing differences in the comparison process to deduce information which leads to bypass authentication.

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.9%

Related for VERACODE:45206