CWE-307
650 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (650)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Manag...Show more |
1Schneider Electric 1Conext Combox Firmware Jun 17, 2026 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on...Show more |
1Snapav 1Wattbox Wb 300 Ip 3 Firmware Jun 17, 2026 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login.
|
1Lexmark 128B2236 Firmware B2338 FirmwareB2442 Firmware+125 moreJun 17, 2026 Jan 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. |
HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced.
User should be locked out for multiple invalid attempts.
|
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue. |
Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1. |
Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded. |
Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that pro...Show more |
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3,...Show more |
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on...Show more |
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2. |
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vu...Show more |
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0. |
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The m...Show more |
1Aiphone 4Gt Db Vn Firmware Gt Dmb Lvn FirmwareGt Dmb N Firmware+1 moreJun 17, 2026 Nov 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allows an attacker to gain administrative privileges. |
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
|
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. |
1Citrix 2Application Delivery Controller Firmware GatewayJun 17, 2026 Nov 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User login brute force protection functionality bypass
|
PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts. |