VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 21 of 32
  • CVE-2026-43914HigMay 11, 2026
    risk 0.40cvss 7.3epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2fa-function send_email_login…

  • CVE-2026-35902MedApr 27, 2026
    risk 0.40cvss 6.2epss 0.00

    The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent…

  • CVE-2025-46606MedApr 17, 2026
    risk 0.40cvss 6.2epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this…

  • CVE-2024-39917HigJul 12, 2024
    risk 0.40cvss 7.2epss 0.01

    xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in…

  • CVE-2024-3461MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.

  • CVE-2014-2875MedFeb 6, 2020
    risk 0.40cvss 6.1epss 0.02

    The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 were SPLIT from this ID.

  • CVE-2026-48071MedAug 6, 2026
    risk 0.38cvss 5.8epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared…

  • CVE-2026-11915MedJul 10, 2026
    risk 0.38cvss 5.9epss 0.00

    vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

  • CVE-2026-41213MedApr 23, 2026
    risk 0.38cvss 5.9epss 0.00

    @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts…

  • CVE-2025-36363MedMar 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-36064MedSep 22, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-52392MedAug 13, 2025
    risk 0.38cvss 5.4epss 0.01

    Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized administrative access. This vulnerability…

  • CVE-2024-45589MedSep 5, 2024
    risk 0.38cvss 5.9epss 0.01

    RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

  • CVE-2024-28833MedJun 10, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.

  • CVE-2024-28825MedApr 24, 2024
    risk 0.38cvss 5.9epss 0.01

    Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.

  • CVE-2023-36917MedJul 11, 2023
    risk 0.38cvss 5.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although…

  • CVE-2023-33868MedJul 6, 2023
    risk 0.38cvss 5.9epss 0.01

    The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.

  • CVE-2022-30076MedApr 16, 2023
    risk 0.38cvss 5.3epss 0.04

    ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

  • CVE-2025-6015MedAug 1, 2025
    risk 0.37cvss 5.7epss 0.00

    Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

  • CVE-2021-36285MedSep 28, 2021
    risk 0.37cvss 5.7epss 0.00

    Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.