VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 15 of 32
  • CVE-2021-20415HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.

  • CVE-2021-28127HigJul 1, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

  • CVE-2020-26556HigMay 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable…

  • CVE-2021-28248HigMar 26, 2021
    risk 0.49cvss 7.5epss 0.01

    CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a…

  • CVE-2021-25676HigMar 15, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions.…

  • CVE-2021-27188HigFeb 12, 2021
    risk 0.49cvss 7.5epss 0.02

    The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.

  • CVE-2021-3138HigJan 14, 2021
    risk 0.49cvss 7.5epss 0.03

    In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

  • CVE-2020-35586HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase…

  • CVE-2020-35585HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.

  • CVE-2020-25827HigSep 27, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests…

  • CVE-2020-7525HigAug 31, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.

  • CVE-2020-13617HigAug 26, 2020
    risk 0.49cvss 7.5epss 0.01

    The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

  • CVE-2020-4400HigJul 22, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.

  • CVE-2020-4232HigMay 28, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.

  • CVE-2020-12752HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020).

  • CVE-2020-10876HigMay 4, 2020
    risk 0.49cvss 7.5epss 0.01

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows…

  • CVE-2020-11650HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.

  • CVE-2019-13166HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.

  • CVE-2013-1895HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.03

    The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

  • CVE-2013-2257HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.02

    Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness