CWE-307
607 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline di...Show more |
1Ibm 1Spectrum Protect Server Jun 17, 2026 Jun 30, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker co...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protec...Show more |
117ido 1Topidp3000 Topsec Operating System Jun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie. |
1Verbatim 2Gd25lk01 3637 C Firmware Keypad Secure Usb 3.2 Gen 1 FirmwareJun 17, 2026 Jun 8, 2022 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring a reformat of the drive after 20 failed unlock attempts) does not work as specified. More than 20 a...Show more |
1Verbatim 2Keypad Secure Usb 3.2 Gen 1 Firmware Store 'n' Go Secure Portable Hdd FirmwareJun 17, 2026 Jun 8, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline brute-force attack for determining the correct passcode, and thus gaining unauthorized access to the...Show more |
1Schneider Electric 2Wiser Smart Eer21000 Firmware Wiser Smart Eer21001 FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses brute force. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5...Show more |
1Dell 3Unity Operating Environment Unity Xt Operating EnvironmentUnityvsa Operating EnvironmentJun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability...Show more |
1Telecomsoftware 2Samwin Agent Samwin Contact CenterNov 21, 2024 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Pas...Show more |
1Siemens 4Desigo Dxr2 Firmware Desigo Pxc3 FirmwareDesigo Pxc4 Firmware+1 moreJun 17, 2026 May 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142....Show more |
1Carrier 1Hills Comnav Firmware Jun 17, 2026 Apr 20, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Version 3002-19 interface, which allows local attackers to brute-force credentials. |
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised...Show more |
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and th...Show more |
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password. |
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk...Show more |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Evf2 Firmware+3 moreJun 17, 2026 Jan 28, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to the charging station web interface by performing brute force attacks. A...Show more |
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP b...Show more |
Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploi...Show more |
1M Files 2M Files Server M Files WebJun 17, 2026 Jan 18, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts ea...Show more |