VulnerabilityModified
CVE-2014-9749
Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."
MEDIUM 4.0EPSS 11.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 11.44% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- squid-cache/squid · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://bugs.squid-cache.org/show_bug.cgi?id=4066
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00052.html
- http://www.openwall.com/lists/oss-security/2015/10/01/1
- http://www.openwall.com/lists/oss-security/2015/10/11/4
- http://www.openwall.com/lists/oss-security/2015/10/12/2
- http://bugs.squid-cache.org/show_bug.cgi?id=4066
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00052.html
- http://www.openwall.com/lists/oss-security/2015/10/01/1
- http://www.openwall.com/lists/oss-security/2015/10/11/4
- http://www.openwall.com/lists/oss-security/2015/10/12/2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.