← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ricoh
4Sp C250dn Firmware
Sp C250sf FirmwareSp C252dn Firmware+1 more
Jun 17, 2026
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by b...Show more
Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.Show less
1Xerox
1Phaser 3320 Firmware
Jun 17, 2026
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
1Hunesion
1I Onenet
Nov 21, 2024
Feb 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.
1Linksys
1Spa2102 Firmware
Nov 21, 2024
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force...Show more
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.Show less
1Keplerproject
1Cgilua
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 an...Show more
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 were SPLIT from this ID.Show less
2Fedoraproject
Python
2Fedora
Py Bcrypt
Nov 21, 2024
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be ov...Show more
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.Show less
1Pwgen Project
1Pwgen
Nov 21, 2024
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jan 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
1Hikvision
1Ds 7204hghi F1 Firmware
Jun 17, 2026
Jan 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it...Show more
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
1Omron
3Plc Cj Firmware
Plc Cs FirmwarePlc Nj Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts withi...Show more
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.Show less
1Weidmueller
40Ie Sw Pl08m 6tx 2sc Firmware
Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.
1Saltstack
1Saltstack
Nov 21, 2024
Dec 3, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
SaltStack RSA Key Generation allows remote users to decrypt communications
1Huawei
1Honor Play Firmware
Jun 17, 2026
Nov 29, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without u...Show more
Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lock. Successful exploit could cause an information disclosure condition.Show less
1Huawei
2Hisuite
Hwbackup
Jun 17, 2026
Nov 29, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawei smartphone user bac...Show more
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawei smartphone user backup information can be obtained by brute forcing the password for encrypting the backup.Show less
1Pimcore
1Pimcore
Jun 17, 2026
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
1Pimcore
1Pimcore
Jun 17, 2026
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
1Autopi
24g/lte Firmware
Wi Fi/nb Firmware
Jun 17, 2026
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi...Show more
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi SSID are derived from the same hash function output (input is only 8 characters), which allows an attacker to deduce the WiFi password from the WiFi SSID.Show less
1Bludit
1Bludit
Jun 17, 2026
Oct 6, 2019
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.