CWE-307
Improper Restriction of Excessive Authentication Attempts
Description
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (623)
page 15 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20415 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217. | ||
| CVE-2021-28127 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2021 | An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur. | ||
| CVE-2020-26556 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2021 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable… | ||
| CVE-2021-28248 | Hig | 0.49 | 7.5 | 0.01 | Mar 26, 2021 | CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a… | ||
| CVE-2021-25676 | Hig | 0.49 | 7.5 | 0.01 | Mar 15, 2021 | A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions.… | ||
| CVE-2021-27188 | Hig | 0.49 | 7.5 | 0.02 | Feb 12, 2021 | The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account. | ||
| CVE-2021-3138 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2021 | In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms. | ||
| CVE-2020-35586 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2020 | In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase… | ||
| CVE-2020-35585 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2020 | In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities. | ||
| CVE-2020-25827 | Hig | 0.49 | 7.5 | 0.02 | Sep 27, 2020 | An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests… | ||
| CVE-2020-7525 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2020 | Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used. | ||
| CVE-2020-13617 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2020 | The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts. | ||
| CVE-2020-4400 | Hig | 0.49 | 7.5 | 0.02 | Jul 22, 2020 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478. | ||
| CVE-2020-4232 | Hig | 0.49 | 7.5 | 0.01 | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336. | ||
| CVE-2020-12752 | Hig | 0.49 | 7.5 | 0.00 | May 11, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020). | ||
| CVE-2020-10876 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows… | ||
| CVE-2020-11650 | Hig | 0.49 | 7.5 | 0.03 | Apr 8, 2020 | An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent. | ||
| CVE-2019-13166 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks. | ||
| CVE-2013-1895 | Hig | 0.49 | 7.5 | 0.03 | Jan 28, 2020 | The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten. | ||
| CVE-2013-2257 | Hig | 0.49 | 7.5 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness |
- risk 0.49cvss 7.5epss 0.01
IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
- risk 0.49cvss 7.5epss 0.01
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable…
- risk 0.49cvss 7.5epss 0.01
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions.…
- risk 0.49cvss 7.5epss 0.02
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.
- risk 0.49cvss 7.5epss 0.03
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
- risk 0.49cvss 7.5epss 0.01
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase…
- risk 0.49cvss 7.5epss 0.01
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests…
- risk 0.49cvss 7.5epss 0.01
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.
- risk 0.49cvss 7.5epss 0.01
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
- risk 0.49cvss 7.5epss 0.02
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.
- risk 0.49cvss 7.5epss 0.01
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020).
- risk 0.49cvss 7.5epss 0.01
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows…
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.
- risk 0.49cvss 7.5epss 0.01
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
- risk 0.49cvss 7.5epss 0.03
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.
- risk 0.49cvss 7.5epss 0.02
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness