← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chshcms
1Cscms
Jun 17, 2026
Dec 27, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
18cms
1Ljcms
Jun 17, 2026
Dec 27, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
2Sandisk
Zendesk
3Enc Datavault
Enc VaultapiSecureaccess
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
1Huntflow
1Huntflow Enterprise
Jun 17, 2026
Dec 10, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for...Show more
Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.Show less
1Businessdnasolutions
1Topease
Jun 17, 2026
Nov 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, whi...Show more
Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges.Show less
1Ibm
1Sterling Connect\
Jun 17, 2026
Nov 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
1Asus
18Gt Ax11000 Firmware
Rt Ax3000 FirmwareRt Ax55 Firmware+15 more
Jul 9, 2026
Nov 19, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZA...Show more
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.Show less
1Ionic
1Identity Vault
Jun 17, 2026
Nov 19, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.
1Fimer
1Aurora Vision
Jun 17, 2026
Nov 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute...Show more
An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.Show less
1Elabftw
1Elabftw
Jun 17, 2026
Oct 22, 2021
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID...Show more
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Cookie header. This issue has been addressed by implementing brute force login protection, as recommended by Owasp with Device Cookies. This mechanism will not impact users and will effectively thwart any brute-force attempts at guessing passwords. The only correct way to address this is to upgrade to version 4.1.0. Adding rate limitation upstream of the eLabFTW service is of course a valid option, with or without upgrading.Show less
2Debian
Gnu
2Debian Linux
Mailman
Jun 17, 2026
Oct 21, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
1Inhandnetworks
1Ir615 Firmware
Jun 17, 2026
Oct 19, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack wit...Show more
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack with no time limitation and without harming the normal operation of the user. This could allow an attacker to gain valid credentials for the product interface.Show less
1Dell
21Latitude 5310 2 In 1 Firmware
Latitude 5320 FirmwareLatitude 5400 Firmware+18 more
Jun 17, 2026
Sep 28, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt miti...Show more
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.Show less
1Dell
21Latitude 5310 2 In 1 Firmware
Latitude 5320 FirmwareLatitude 5400 Firmware+18 more
Jun 17, 2026
Sep 28, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mit...Show more
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
Sep 16, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-For...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.Show less
1Bab Technologie
1Eibport Firmware
Jun 17, 2026
Sep 9, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-ca...Show more
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-calculated in a brute force attack against BMX interface. This is usable and part of an attack chain to gain SSH root access.Show less
1Bab Technologie
1Eibport Firmware
Jun 17, 2026
Sep 9, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The password could be weak and default userna...Show more
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The password could be weak and default username is known as 'admin'. This is usable and part of an attack chain to gain SSH root access.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Sep 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php
1Vmware
4Cloud Foundation
Identity ManagerVrealize Suite Lifecycle Manager+1 more
Jun 17, 2026
Aug 31, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint,...Show more
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Aug 17, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible t...Show more
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to. *This bug only affects Firefox on Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91 and Thunderbird < 91.Show less