VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 19 of 32
  • CVE-2024-57610HigFeb 6, 2025
    risk 0.42cvss 7.5epss 0.01

    A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core…

  • CVE-2024-53647MedDec 31, 2024
    risk 0.42cvss 6.5epss 0.00

    Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service.

  • CVE-2024-38488MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the…

  • CVE-2024-5682MedSep 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation. This issue affects Yordam Library Automation System: before 20.1.

  • CVE-2024-25031MedJun 28, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678.

  • CVE-2024-28022MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted…

  • CVE-2024-21662HigMar 18, 2024
    risk 0.42cvss 7.5epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mechanism. This loophole in…

  • CVE-2024-24721MedFeb 27, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access the administration panel

  • CVE-2024-22425MedFeb 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint…

  • CVE-2015-20110HigOct 31, 2023
    risk 0.42cvss 7.5epss 0.01

    JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course…

  • CVE-2023-3605MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication…

  • CVE-2023-33754MedJun 1, 2023
    risk 0.42cvss 6.5epss 0.01

    The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.

  • CVE-2023-29005HigApr 10, 2023
    risk 0.42cvss 7.5epss 0.01

    Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and setting an `AUTH_RATE_LIMIT`.

  • CVE-2023-26476HigMar 2, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to versions 14.7-rc-1, 13.4.4, or 13.10.9 and…

  • CVE-2023-0860HigFeb 16, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.

  • CVE-2023-25156HigFeb 15, 2023
    risk 0.42cvss 7.5epss 0.01

    Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and…

  • CVE-2022-40903MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allows an attacker to gain administrative privileges.

  • CVE-2022-33735MedSep 20, 2022
    risk 0.42cvss 6.5epss 0.00

    There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwords, which may cause sensitive system information to be disclosed.

  • CVE-2022-2822HigAug 15, 2022
    risk 0.42cvss 7.5epss 0.01

    An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.

  • CVE-2022-22496MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.00

    While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.