AirWatch contains a flaw that is triggered when the ASP.NET_SessionId cookie is deleted. This will cause the program to no longer supply the CAPTCHA test until 3 more unsuccessful login attempts occur. This may allow a remote attacker to bypass CAPTCHA protection and more easily conduct brute force attacks.
Disclosure Timeline:
Disclosure Date :2013-01-28
Exploit Publish Date :2013-01-28