Revive Adserver · Revive Adserver · CVE-2016-9124
**Name of the Vulnerable Software and Affected Versions**
Revive Adserver versions prior to 3.2.3
**Description**
The issue allows for password-guessing attacks due to improper restriction of excessive authentication attempts on the login page. A countermeasure has been introduced, including a random delay in case of password failures and a system to discourage parallel brute forcing, aiming to allow valid users to log in even during an attack.
**Recommendations**
For versions prior to 3.2.3, update to version 3.2.3 or later to resolve the issue.