Tomahawk auth timing attack due to usage of strcmp has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Hiawatha | Hiawatha-webserver | 11.7 (including) | 11.7 (including) |
References