PT-2023-20779 · Unknown · Revive Adserver

CVE-2023-26756

·

Publicado

2023-04-14

·

Atualizado

2024-08-02

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Revive Adserver version 5.4.1
Description The login page of Revive Adserver is vulnerable to brute force attacks. The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
Recommendations For Revive Adserver version 5.4.1, consider implementing additional security measures to mitigate the risk of brute force attacks, such as further restricting login attempts or enhancing password requirements, as the vendor's existing mitigations may not be sufficient for all users.

Exploit

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26756

Produtos afetados

Revive Adserver