PT-2023-20779 · Unknown · Revive Adserver

CVE-2023-26756

·

Published

2023-04-14

·

Updated

2024-08-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Revive Adserver version 5.4.1
Description The login page of Revive Adserver is vulnerable to brute force attacks. The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
Recommendations For Revive Adserver version 5.4.1, consider implementing additional security measures to mitigate the risk of brute force attacks, such as further restricting login attempts or enhancing password requirements, as the vendor's existing mitigations may not be sufficient for all users.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26756

Affected Products

Revive Adserver