PT-2024-20075 · Darkhttpd · Darkhttpd

Matthias Gerstner

·

Published

2024-01-21

·

Updated

2026-03-29

·

CVE-2024-23771

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions darkhttpd versions prior to 1.15
Description The issue arises from the use of strcmp (which is not constant time) to verify authentication, making it easier for remote attackers to bypass authentication via a timing side channel. This allows attackers to potentially gain unauthorized access.
Recommendations For versions prior to 1.15, update to version 1.15 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the server to minimize the risk of exploitation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-23771

Affected Products

Darkhttpd