← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Anuko
1Time Tracker
Jun 17, 2026
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
1Clickstudios
1Passwordstate
Jun 17, 2026
Oct 29, 2020
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attack...Show more
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code. As result, remote attacker retrieves all passwords from another systems, available for affected account.Show less
1Tiki
1Tiki
Jun 17, 2026
Oct 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
1Sonicwall
2Sonicos
Sonicosv
Jun 17, 2026
Oct 12, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 versi...Show more
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.Show less
2Nextcloud
Opensuse
3Backports Sle
LeapPreferred Providers
Jun 17, 2026
Oct 5, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
Sep 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is...Show more
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.Show less
1Gradle
1Enterprise
Jun 17, 2026
Sep 18, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 14, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.
1Siemens
4Simatic Hmi Basic Panels 2nd Generation Firmware
Simatic Hmi Comfort Panels FirmwareSimatic Hmi Mobile Panels Firmware+1 more
Jun 17, 2026
Sep 9, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Pa...Show more
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.Show less
1Schneider Electric
2Spacelynk Firmware
Wiser For Knx Firmware
Jun 17, 2026
Aug 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute forc...Show more
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 31, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
1Mitel
116863 Firmware
6865 Firmware6867 Firmware+8 more
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed l...Show more
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.Show less
1Umanni
1Human Resources
Jun 17, 2026
Aug 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
1Nextcloud
1Preferred Providers
Jun 17, 2026
Jul 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
1Nec
2Um4730 Firmware
Um8000 Firmware
Jun 17, 2026
Jul 29, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.
1Ibm
1Security Key Lifecycle Manager
Jun 17, 2026
Jul 29, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.
1Ibm
1Verify Gateway
Jun 17, 2026
Jul 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.
1Openclinic Ga Project
1Openclinic Ga
Jun 17, 2026
Jul 20, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to...Show more
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.Show less
1Openclinic Ga Project
1Openclinic Ga
Jun 17, 2026
Jul 20, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.
1Ufactory
1Xarm 5 Lite Firmware
Jun 17, 2026
Jul 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.