← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Linux
2Fedora
Linux Kernel
Jun 17, 2026
Mar 30, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which ca...Show more
An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which can cause a system crash upon an unexpected access attempt (in map_create in kernel/bpf/syscall.c or check_btf_info in kernel/bpf/verifier.c), aka CID-350a5c4dd245.Show less
1Broadcom
1Ehealth
Jun 17, 2026
Mar 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using d...Show more
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Advantech
1Spectre Rt Ert351 Firmware
Jun 17, 2026
Mar 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.
1Ibm
1Spectrum Scale
Jun 17, 2026
Mar 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.
1Siemens
4Ruggedcom Rm1224 Firmware
Scalance M 800 FirmwareScalance S615 Firmware+1 more
Jun 17, 2026
Mar 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger...Show more
A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions. When triggered, the device will reboot automatically.Show less
1Gigaset
1Dx600a Firmware
Jun 17, 2026
Mar 2, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4...Show more
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.Show less
1Eyesofnetwork
1Eyesofnetwork
Jun 17, 2026
Feb 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
1Mbconnectline
2Mbconnect24
Mymbconnect24
Jun 17, 2026
Feb 16, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
1Xn B1agzlht
1Fx Aggregator Terminal Client
Jun 17, 2026
Feb 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.
1Logitech
1Lan Wh450n/gr Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.
1Discourse
1Discourse
Jun 17, 2026
Jan 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
1Cisco
2Webex Meetings
Webex Meetings Server
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is du...Show more
A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Webex Meetings Server site. A successful exploit would require the attacker to have access to join a Webex meeting, including applicable meeting join links and passwords. A successful exploit could allow the attacker to acquire or take over the host role for a meeting.Show less
1Mersive
1Solstice Pod Firmware
Jun 17, 2026
Dec 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requi...Show more
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).Show less
1Mersive
1Solstice Pod Firmware
Jun 17, 2026
Dec 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.
1Moxa
1Nport Iaw5000a I/o Firmware
Jun 17, 2026
Dec 23, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.
1Limitloginattempts
1Limit Login Attempts Reloaded
Jun 17, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configur...Show more
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.Show less
1Bitrix24
1Bitrix Framework
Jun 17, 2026
Dec 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a...Show more
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.Show less
1Cpanel
1Cpanel
Jun 17, 2026
Nov 27, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
1Bigbluebutton
1Bigbluebutton
Jun 17, 2026
Nov 26, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
1Schneider Electric
1Ecostruxure Control Expert
Jun 17, 2026
Nov 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution whe...Show more
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.Show less