CWE-307
607 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which ca...Show more |
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using d...Show more |
1Advantech 1Spectre Rt Ert351 Firmware Jun 17, 2026 Mar 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack. |
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974. |
1Siemens 4Ruggedcom Rm1224 Firmware Scalance M 800 FirmwareScalance S615 Firmware+1 moreJun 17, 2026 Mar 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger...Show more |
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4...Show more |
1Eyesofnetwork 1Eyesofnetwork Jun 17, 2026 Feb 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation). |
1Mbconnectline 2Mbconnect24 Mymbconnect24Jun 17, 2026 Feb 16, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default. |
1Xn B1agzlht 1Fx Aggregator Terminal Client Jun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account. |
1Logitech 1Lan Wh450n/gr Firmware Jun 17, 2026 Feb 12, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network. |
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms. |
1Cisco 2Webex Meetings Webex Meetings ServerJun 17, 2026 Jan 13, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is du...Show more |
1Mersive 1Solstice Pod Firmware Jun 17, 2026 Dec 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requi...Show more |
1Mersive 1Solstice Pod Firmware Jun 17, 2026 Dec 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities. |
1Moxa 1Nport Iaw5000a I/o Firmware Jun 17, 2026 Dec 23, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication. |
1Limitloginattempts 1Limit Login Attempts Reloaded Jun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configur...Show more |
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a...Show more |
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575). |
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code. |
1Schneider Electric 1Ecostruxure Control Expert Jun 17, 2026 Nov 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution whe...Show more |