CWE-307
649 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (649)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Jul 20, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks. |
1Ufactory 1Xarm 5 Lite Firmware Jun 17, 2026 Jul 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access. |
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page. |
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA. |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Jun 16, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force. |
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach. |
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020). |
1Foxitsoftware 2Phantompdf ReaderJun 17, 2026 Jun 4, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures. |
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857. |
1Ibm 1Security Identity Governance And Intelligence Jun 17, 2026 May 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 17...Show more |
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-...Show more |
In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but on...Show more |
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attac...Show more |
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it prope...Show more |
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. |
1Ixsystems 2Freenas Firmware Truenas FirmwareJun 17, 2026 Apr 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication m...Show more |
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts witho...Show more |
1Juniper 2Advanced Threat Protection Virtual Advanced Threat ProtectionJun 17, 2026 Apr 8, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an un...Show more |
HCL AppScan Standard is vulnerable to excessive authorization attempts |
1Cacagoo 1Tv 288zd 2mp Firmware Jun 17, 2026 Apr 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required. |