CVE-2008-0915

The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookie's value.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ipdiva:ipdiva:*:*:*:*:*:*:*:*
cpe:2.3:a:ipdiva:ipdiva:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:43

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060314.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060314.html -
References () http://secunia.com/advisories/28963 - Vendor Advisory () http://secunia.com/advisories/28963 - Vendor Advisory
References () http://securityreason.com/securityalert/3692 - () http://securityreason.com/securityalert/3692 -
References () http://www.securityfocus.com/archive/1/488133/100/100/threaded - () http://www.securityfocus.com/archive/1/488133/100/100/threaded -
References () http://www.securityfocus.com/bid/27800 - () http://www.securityfocus.com/bid/27800 -

Information

Published : 2008-02-22 23:44

Updated : 2024-11-21 00:43


NVD link : CVE-2008-0915

Mitre link : CVE-2008-0915

CVE.ORG link : CVE-2008-0915


JSON object : View

Products Affected

ipdiva

  • ipdiva