← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lexmark
128B2236 Firmware
B2338 FirmwareB2442 Firmware+125 more
Jun 17, 2026
Jan 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
1Hcltech
1Bigfix Mobile
Jun 17, 2026
Jan 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.
1Easyvista
1Service Manager
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Dec 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.
1Planetestream
1Planet Estream
Jun 17, 2026
Dec 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that pro...Show more
Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.Show less
1Fortinet
2Fortideceptor
Fortisandbox
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3,...Show more
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.Show less
1Checkpoint
1Ssl Network Extender
Jun 17, 2026
Nov 30, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on...Show more
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.Show less
1Wger
1Wger
Jun 17, 2026
Nov 24, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
1Maarch
1Maarch Rm
Jul 9, 2026
Nov 23, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vu...Show more
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.Show less
1Joinmastodon
1Mastodon
Jun 17, 2026
Nov 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The m...Show more
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716.Show less
1Aiphone
4Gt Db Vn Firmware
Gt Dmb Lvn FirmwareGt Dmb N Firmware+1 more
Jun 17, 2026
Nov 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allows an attacker to gain administrative privileges.
1Kavitareader
1Kavita
Jun 17, 2026
Nov 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
1Kavitareader
1Kavita
Jun 17, 2026
Nov 11, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
1Citrix
2Application Delivery Controller Firmware
Gateway
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
User login brute force protection functionality bypass
1Pwndoc Project
1Pwndoc
Jun 17, 2026
Oct 30, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.
1Pwndoc Project
1Pwndoc
Jun 17, 2026
Oct 30, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.
1Chatwoot
1Chatwoot
Jun 17, 2026
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accoun...Show more
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.Show less
1Getkirby
1Kirby
Jun 17, 2026
Oct 24, 2022
N/A· v4
3.7 LOW· v3
N/A· v2
Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you o...Show more
Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth method with the `auth.methods` option or if you have enabled the `debug` option in production. By using two or more IP addresses and multiple login attempts, valid user accounts will lock, but invalid accounts will not, leading to account enumeration. This issue has been patched in versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1. If you cannot update immediately, you can work around the issue by setting the `auth.methods` option to `password`, which disables the code-based login and password reset forms.Show less