Vulnerability Description
An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-37015?
CVE-2024-37015 is a vulnerability with a CVSS score of 7.4 (HIGH). An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hos...
How severe is CVE-2024-37015?
CVE-2024-37015 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-37015?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.