Описание
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| hiawatha | itp | package |
EPSS
Процентиль: 5%
0.00154
Низкий
Связанные уязвимости
CVSS3: 3.3
nvd
7 месяцев назад
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
CVSS3: 4
github
7 месяцев назад
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
EPSS
Процентиль: 5%
0.00154
Низкий