VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 10 of 32
  • CVE-2025-12995HigDec 4, 2025
    risk 0.53cvss 8.1epss 0.00

    Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

  • CVE-2025-56224HigOct 20, 2025
    risk 0.53cvss 8.1epss 0.00

    A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

  • CVE-2025-46414HigAug 8, 2025
    risk 0.53cvss 8.1epss 0.00

    The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial number. The API provides clear feedback…

  • CVE-2025-46739HigMay 12, 2025
    risk 0.53cvss 8.1epss 0.00

    An unauthenticated user could discover account credentials via a brute-force attack without rate limiting

  • CVE-2025-42600HigApr 23, 2025
    risk 0.53cvss epss 0.00

    This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP,…

  • CVE-2024-12039HigMar 20, 2025
    risk 0.53cvss 8.1epss 0.01

    langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated attacker to reset owner, admin, or other user passwords within a few hours by guessing the six-digit…

  • CVE-2024-23106HigJan 14, 2025
    risk 0.53cvss 8.1epss 0.01

    An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.

  • CVE-2024-45404HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication…

  • CVE-2021-22530HigAug 28, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ…

  • CVE-2024-38176HigJul 23, 2024
    risk 0.53cvss 8.1epss 0.01

    An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.

  • CVE-2023-50123HigJan 11, 2024
    risk 0.53cvss 8.1epss 0.01

    The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS authentication, to bring the alarm system to a disarmed state.

  • CVE-2022-42478HigJun 13, 2023
    risk 0.53cvss 8.1epss 0.01

    An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints.

  • CVE-2022-38491HigJan 10, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.

  • CVE-2022-35846HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.01

    An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.

  • CVE-2022-31228HigOct 12, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can potentially exploit this vulnerability and gain access to an admin account.

  • CVE-2022-31234HigJul 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible…

  • CVE-2022-29084HigJun 2, 2022
    risk 0.53cvss 8.1epss 0.02

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as…

  • CVE-2022-22561HigApr 12, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.

  • CVE-2022-22553HigJan 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing.…

  • CVE-2013-2228HigDec 3, 2019
    risk 0.53cvss 8.1epss 0.02

    SaltStack RSA Key Generation allows remote users to decrypt communications