The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15688
Reference (s):
- https://github.com/embedthis/goahead-gpl/issues/3
- http://packetstormsecurity.com/files/159505/EmbedThis-GoAhead-Web-Server-5.1.1-Digest-Authentication-Capture-Replay-Nonce-Reuse.html
- https://github.com/embedthis/goahead-gpl/issues/3

