The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookies value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ipdiva | Ipdiva | * | 2.2.8 (including) |
Ipdiva | Ipdiva | * | 2.3.2 (including) |