Improper Authentication Management in Revive Adserver by Revive
CVE-2016-9124

9.8CRITICAL

Key Information:

Vendor
CVE Published:
28 March 2017

What is CVE-2016-9124?

Revive Adserver versions prior to 3.2.3 are susceptible to improper authentication management that allows password-guessing attacks on the login page. While an account lockdown feature was considered for better security, it was ultimately deemed disruptive for legitimate users during attack scenarios. To mitigate these risks, a random delay was implemented after failed password attempts, along with measures to prevent simultaneous brute-force attempts, ensuring that valid users are still able to access the adserver during ongoing attacks.

Affected Version(s)

Revive Adserver All before 3.2.3 Revive Adserver All versions before 3.2.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.