VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 20 of 32
  • CVE-2013-10004MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Incorrect implementation of a hashing…

  • CVE-2021-29987MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.01

    After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not…

  • CVE-2021-38155HigAug 6, 2021
    risk 0.42cvss 7.5epss 0.02

    OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times,…

  • CVE-2021-3663HigJul 25, 2021
    risk 0.42cvss 7.5epss 0.01

    firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts

  • CVE-2021-20635MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.

  • CVE-2020-28206MedDec 2, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group.…

  • CVE-2020-29136MedNov 27, 2020
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

  • CVE-2020-5141MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7…

  • CVE-2020-13312MedSep 14, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

  • CVE-2020-8827HigApr 8, 2020
    risk 0.42cvss 7.5epss 0.02

    As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.

  • CVE-2019-18917MedMar 16, 2020
    risk 0.42cvss 6.5epss 0.01

    A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.

  • CVE-2019-18986HigNov 15, 2019
    risk 0.42cvss 7.5epss 0.01

    Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.

  • CVE-2018-19021MedJan 25, 2019
    risk 0.42cvss 6.5epss 0.01

    A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker to cause a denial of service.

  • CVE-2026-43926MedJun 4, 2026
    risk 0.41cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSBilling's rate limiter, which only…

  • CVE-2026-1816MedMay 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13.

  • CVE-2025-10928MedOct 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5.

  • CVE-2025-36758MedSep 10, 2025
    risk 0.41cvss epss 0.00

    It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.

  • CVE-2023-49810HigJan 10, 2024
    risk 0.41cvss 7.3epss 0.01

    A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An…

  • CVE-2021-38474MedOct 19, 2021
    risk 0.41cvss 6.3epss 0.01

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack with no time limitation and without harming the normal…

  • CVE-2026-45364HigMay 28, 2026
    risk 0.40cvss 7.3epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients…