Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9124

Опубликовано: 28 мар. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to avoid introducing service disruptions to regular users during such attacks. A random delay has instead been introduced as a countermeasure in case of password failures, along with a system to discourage parallel brute forcing. These systems will effectively allow the valid users to log in to the adserver, even while an attack is in progress.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
Версия до 3.2.2 (включая)

EPSS

Процентиль: 73%
0.00773
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307
CWE-287

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to avoid introducing service disruptions to regular users during such attacks. A random delay has instead been introduced as a countermeasure in case of password failures, along with a system to discourage parallel brute forcing. These systems will effectively allow the valid users to log in to the adserver, even while an attack is in progress.

EPSS

Процентиль: 73%
0.00773
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307
CWE-287
Уязвимость CVE-2016-9124