PT-2023-20779 · Unknown · Revive Adserver
CVE-2023-26756
·
Publicado
2023-04-14
·
Atualizado
2024-08-02
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Revive Adserver version 5.4.1
Description
The login page of Revive Adserver is vulnerable to brute force attacks. The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
Recommendations
For Revive Adserver version 5.4.1, consider implementing additional security measures to mitigate the risk of brute force attacks, such as further restricting login attempts or enhancing password requirements, as the vendor's existing mitigations may not be sufficient for all users.
Exploit
Correção
Improper Restriction of Excessive Authentication Attempts
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Revive Adserver