PT-2023-20779 · Unknown · Revive Adserver
CVE-2023-26756
·
Published
2023-04-14
·
Updated
2024-08-02
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Revive Adserver version 5.4.1
Description
The login page of Revive Adserver is vulnerable to brute force attacks. The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
Recommendations
For Revive Adserver version 5.4.1, consider implementing additional security measures to mitigate the risk of brute force attacks, such as further restricting login attempts or enhancing password requirements, as the vendor's existing mitigations may not be sufficient for all users.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Revive Adserver