VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 14 of 32
  • CVE-2022-43904HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.

  • CVE-2022-32757HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510.

  • CVE-2023-23755HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

  • CVE-2022-43377HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)

  • CVE-2023-26756HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.

  • CVE-2023-24020HigJan 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login.

  • CVE-2022-23746HigNov 30, 2022
    risk 0.49cvss 7.5epss 0.01

    The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.

  • CVE-2022-37772HigNov 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.

  • CVE-2022-37145HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.01

    The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt…

  • CVE-2021-22640HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

  • CVE-2022-22452HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.

  • CVE-2022-24044HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does…

  • CVE-2021-22818HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to the charging station web interface by performing brute force attacks. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All…

  • CVE-2021-41807HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.

  • CVE-2021-42544HigNov 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges.

  • CVE-2021-38890HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.

  • CVE-2021-22003HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy…

  • CVE-2021-20427HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.

  • CVE-2021-27943HigAug 2, 2021
    risk 0.49cvss 7.5epss 0.01

    The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forcefully pair the device, leading to remote control of the TV…

  • CVE-2020-23283HigJul 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.