VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 12 of 32
  • CVE-2026-24696HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-20882HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-27778HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.01

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-26305HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-24445HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-25945HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.01

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-25114HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-25113HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-20792HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or misrouting legitimate charger telemetry, or conduct…

  • CVE-2026-27521HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials.

  • CVE-2025-67853HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

  • CVE-2025-53968HigJan 22, 2026
    risk 0.49cvss 7.5epss 0.00

    This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (DoS) condition. This can overwhelm the …

  • CVE-2025-59113HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by resetting this parameter. Only version…

  • CVE-2025-60424HigOct 27, 2025
    risk 0.49cvss 7.6epss 0.01

    A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

  • CVE-2025-35041HigSep 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.

  • CVE-2024-49342HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-27456HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.01

    The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • CVE-2025-27449HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.01

    The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • CVE-2025-1710HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.01

    The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • CVE-2025-48014HigMay 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Password guessing limits could be bypassed when using LDAP authentication.