VULNERABILITY INTELLIGENCE
CVE-2016-9124
CVSS score9.8 CRITICAL
EPSS probability2.23%
CISA KEVNot currently listed
Published2017-03-28
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to avoid introducing service disruptions to regular users during such attacks. A random delay has instead been introduced as a countermeasure in case of password failures, along with a system to discourage parallel brute forcing. These systems will effectively allow the valid users to log in to the adserver, even while an attack is in progress.
Weakness classification
- CWE-287: Improper Authentication
- CWE-307: Improper Restriction of Excessive Authentication Attempts
Primary references
- support@hackerone.com — Issue Tracking, Patch, Third Party Advisory
- support@hackerone.com — Permissions Required
- support@hackerone.com — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Issue Tracking, Patch, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Permissions Required
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory