VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 13 of 32
  • CVE-2024-51476HigMar 6, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2024-55008HigJan 7, 2025
    risk 0.49cvss 7.5epss 0.01

    JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts…

  • CVE-2024-49597HigNov 26, 2024
    risk 0.49cvss 7.6epss 0.01

    Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2024-7292HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.

  • CVE-2024-45327HigSep 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators…

  • CVE-2024-41904HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force…

  • CVE-2024-39874HigJul 9, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user…

  • CVE-2024-39873HigJul 9, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its web API. This could allow an attacker to learn user credentials that are…

  • CVE-2024-5862HigJun 24, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med Health Aplication: before 1.0.14.

  • CVE-2024-1104HigFeb 22, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.

  • CVE-2023-45191HigFeb 9, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.

  • CVE-2023-38273HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.

  • CVE-2023-50326HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.

  • CVE-2023-6912HigDec 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.

  • CVE-2023-50444HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows…

  • CVE-2023-41350HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha…

  • CVE-2023-37832HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.

  • CVE-2023-44111HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44096HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-43699HigOct 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.