CWE-307
649 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (649)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code. |
1Schneider Electric 1Ecostruxure Control Expert Jun 17, 2026 Nov 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution whe...Show more |
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox |
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attack...Show more |
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. |
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 versi...Show more |
2Nextcloud Opensuse3Backports Sle LeapPreferred ProvidersJun 17, 2026 Oct 5, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Sep 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is...Show more |
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins. |
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter. |
1Siemens 4Simatic Hmi Basic Panels 2nd Generation Firmware Simatic Hmi Comfort Panels FirmwareSimatic Hmi Mobile Panels Firmware+1 moreJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Pa...Show more |
1Schneider Electric 2Spacelynk Firmware Wiser For Knx FirmwareJun 17, 2026 Aug 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute forc...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Aug 31, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. |
1Mitel 116863 Firmware 6865 Firmware6867 Firmware+8 moreJun 17, 2026 Aug 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed l...Show more |
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page. |
1Nextcloud 1Preferred Providers Jun 17, 2026 Jul 30, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password. |
1Nec 2Um4730 Firmware Um8000 FirmwareJun 17, 2026 Jul 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks. |
1Ibm 1Security Key Lifecycle Manager Jun 17, 2026 Jul 29, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156. |
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478. |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Jul 20, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to...Show more |