← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Talelin
1Lin Cms Flask
Jun 17, 2026
Aug 16, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
1Ibm
1Security Guardium
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
1Openstack
1Keystone
Jun 17, 2026
Aug 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name...Show more
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.Show less
1Vizio
2E50x E1 Firmware
P65 F1 Firmware
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forc...Show more
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forcefully pair the device, leading to remote control of the TV settings and configurations.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Jun 17, 2026
Jul 30, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be a...Show more
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.Show less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Jul 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
1Mv
1Mconnect
Jun 17, 2026
Jul 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enume...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumer...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`)...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` annotation. Risk depends on the installed applications on the Nextcloud Server, but could range from bypassing authentication ratelimits or spamming other Nextcloud users. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. No workarounds aside from upgrading are known to exist.Show less
1Ibm
1Guardium Data Encryption
Jun 17, 2026
Jul 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.
1Qsan
3Sanos
Storage ManagerXevo
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest cont...Show more
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN and refer to recommendations in QSAN Document.Show less
1Stormshield
1Stormshield Network Security
Jun 17, 2026
Jul 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-...Show more
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.Show less
1Apache
1Apisix Dashboard
Jun 17, 2026
Jun 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was u...Show more
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time, the default account and password are fixed.Ultimately these factors lead to the issue of security risks. This issue is fixed in APISIX Dashboard 2.6.1Show less
1Redhat
23scale
3scale Api Management
Jun 17, 2026
Jun 1, 2021
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Jun 17, 2026
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.
1Bluetooth
2Bluetooth Core Specification
Mesh Profile
Jun 17, 2026
May 24, 2021
N/A· v4
7.5 HIGH· v3
2.9 LOW· v2
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out,...Show more
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.Show less
1Invoiceplane
1Invoiceplane
Jun 17, 2026
May 17, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
1Gestsup
1Gestsup
Jun 17, 2026
Apr 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tok...Show more
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.Show less