Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4080-1 | libaws security update |
EUVD |
EUVD-2025-5281 | When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration). |
Mon, 07 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adacore
Adacore ada Web Server Debian Debian debian Linux |
|
| CPEs | cpe:2.3:a:adacore:ada_web_server:25.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Adacore
Adacore ada Web Server Debian Debian debian Linux |
Mon, 10 Mar 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 | |
| Metrics |
cvssV3_1
|
Wed, 26 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-10T20:03:09.509Z
Reserved: 2024-12-09T00:00:00.000Z
Link: CVE-2024-55581
Updated: 2025-03-10T20:03:09.509Z
Status : Analyzed
Published: 2025-02-26T22:15:14.137
Modified: 2025-04-07T18:39:22.837
Link: CVE-2024-55581
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD