CWE-307
607 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox |
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attack...Show more |
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. |
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 versi...Show more |
2Nextcloud Opensuse3Backports Sle LeapPreferred ProvidersJun 17, 2026 Oct 5, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Sep 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is...Show more |
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins. |
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter. |
1Siemens 4Simatic Hmi Basic Panels 2nd Generation Firmware Simatic Hmi Comfort Panels FirmwareSimatic Hmi Mobile Panels Firmware+1 moreJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Pa...Show more |
1Schneider Electric 2Spacelynk Firmware Wiser For Knx FirmwareJun 17, 2026 Aug 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute forc...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Aug 31, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. |
1Mitel 116863 Firmware 6865 Firmware6867 Firmware+8 moreJun 17, 2026 Aug 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed l...Show more |
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page. |
1Nextcloud 1Preferred Providers Jun 17, 2026 Jul 30, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password. |
1Nec 2Um4730 Firmware Um8000 FirmwareJun 17, 2026 Jul 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks. |
1Ibm 1Security Key Lifecycle Manager Jun 17, 2026 Jul 29, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156. |
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478. |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Jul 20, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Jul 20, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks. |
1Ufactory 1Xarm 5 Lite Firmware Jun 17, 2026 Jul 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access. |