← Back

CVE-2014-9749

nvd nist
Published: Nov 6, 2015Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."

Affected (17)

1 product
Squid
1 product
Opensuse
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Squid Cache
Version 3.4.10
Version 3.4.11
Version 3.4.12
Version 3.4.13
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.9
Version 3.5.0.1
Version 3.5.0.2
Version 3.5.0.3
Version 3.5.0.4
Version 3.5.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 13.1
Version 13.2

Related CWEs

Timeline

No history available yet.