Vulnerabilities > CVE-2008-0915 - Unspecified vulnerability in Ipdiva
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookie's value.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060314.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060314.html
- http://secunia.com/advisories/28963
- http://secunia.com/advisories/28963
- http://securityreason.com/securityalert/3692
- http://securityreason.com/securityalert/3692
- http://www.securityfocus.com/archive/1/488133/100/100/threaded
- http://www.securityfocus.com/archive/1/488133/100/100/threaded
- http://www.securityfocus.com/bid/27800
- http://www.securityfocus.com/bid/27800