PT-2025-8751 · Adacore+2 · Aws.Client+3

CVE-2024-55581

·

Published

2025-02-26

·

Updated

2025-04-07

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AdaCore Ada Web Server version 25.0.0
Description The issue concerns a lack of verification of an HTTPS server's certificate in the default behaviour of AWS.Client when linked with GnuTLS, making it vulnerable to a man-in-the-middle attack. This occurs unless the using program specifies a TLS configuration.
Recommendations For AdaCore Ada Web Server version 25.0.0, consider specifying a TLS configuration in the using program to enable verification of an HTTPS server's certificate and mitigate the risk of a man-in-the-middle attack. As a temporary workaround, restrict the use of AWS.Client with default settings to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55581
DLA-4080-1

Affected Products

Aws.Client
Ada Web Server
Debian
Gnutls