← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Venki
1Supravizio Bpm
Jun 17, 2026
Jul 7, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
1Mattermost
1Mattermost Server
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
1Schneider Electric
1Easergy T300 Firmware
Jun 17, 2026
Jun 16, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.
1Royalapps
1Royal Ts
Jun 17, 2026
Jun 9, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.
1Google
1Android
Jun 17, 2026
Jun 4, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
1Foxitsoftware
2Phantompdf
Reader
Jun 17, 2026
Jun 4, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
1Ibm
1Security Guardium
Jun 17, 2026
Jun 4, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
1Ibm
1Security Identity Governance And Intelligence
Jun 17, 2026
May 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 17...Show more
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.Show less
1Google
1Android
Jun 17, 2026
May 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-...Show more
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020).Show less
1Sorcery Project
1Sorcery
Jun 17, 2026
May 7, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but on...Show more
In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. This has been patched in 0.15.0.Show less
1Oklok Project
1Oklok
Jun 17, 2026
May 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attac...Show more
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.Show less
1Oklok Project
1Oklok
Jun 17, 2026
May 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it prope...Show more
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows an attacker to brute force the four-digit verification code in order to bypass email verification and change the password of a victim account.Show less
1Dlink
1Dir 615 Firmware
Jun 17, 2026
Apr 21, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
1Ixsystems
2Freenas Firmware
Truenas Firmware
Jun 17, 2026
Apr 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication m...Show more
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.Show less
1Argoproj
1Argo Cd
Jun 17, 2026
Apr 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts witho...Show more
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.Show less
1Juniper
2Advanced Threat Protection
Virtual Advanced Threat Protection
Jun 17, 2026
Apr 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an un...Show more
Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. Successful exploitation will allow the attacker to perform brute-force password attacks on the SSH service. This issue affects: Juniper Networks JATP and vJATP versions prior to 5.0.6.0.Show less
1Hcltech
1Appscan
Jun 17, 2026
Apr 7, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
HCL AppScan Standard is vulnerable to excessive authorization attempts
1Cacagoo
1Tv 288zd 2mp Firmware
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock passwo...Show more
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-14575 (January 2020).Show less
1Hp
8Deskjet Ink Advantage 5000 M2u86a Firmware
Deskjet Ink Advantage 5000 M2u89b FirmwareEnvy 5000 M2u85a Firmware+5 more
Jun 17, 2026
Mar 16, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.