CWE-307
607 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vzug 1Combi Stream Mslq Firmware Jun 17, 2026 Oct 6, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to au...Show more |
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178. |
1Dell 1Emc Elastic Cloud Storage Jun 17, 2026 Sep 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain...Show more |
1Dell 1Emc Integrated Data Protection Appliance Firmware Jun 17, 2026 Sep 27, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force a...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with...Show more |
1Google 1Nest Cam Iq Indoor Firmware Jun 17, 2026 Aug 20, 2019 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resu...Show more |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Aug 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036. |
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to...Show more |
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters. |
1Microsoft 3Windows Server 2012 Windows Server 2016Windows Server 2019Jun 17, 2026 Jul 15, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a spe...Show more |
1Ibm 1Robotic Process Automation With Automation Anywhere Jun 17, 2026 Jul 1, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411. |
1Ibm 3Intelligent Operations Center Intelligent Operations Center For Emergency ManagementWater Operations For WaternamicsJun 17, 2026 Jun 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013. |
There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking...Show more |
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting tech...Show more |
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File locat...Show more |
1Teltonika 1Rut950 Firmware Nov 21, 2024 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to th...Show more |
1Moxa 4Eds 405a Firmware Eds 408a FirmwareEds 510a Firmware+1 moreJun 17, 2026 Mar 5, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack. |
A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker to cause a denial of s...Show more |
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password] parameters, which might make it easier for remote attackers to obtain access via a brute-...Show more |
1Pivotal Software 2Broker Api On Demand Services SdkNov 21, 2024 Nov 19, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with differen...Show more |