VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 23 of 32
  • CVE-2023-6756MedDec 13, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to…

  • CVE-2023-4625MedNov 6, 2023
    risk 0.35cvss 5.3epss 0.01

    Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/iQ-R Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from logging into the Web server function for a…

  • CVE-2023-46123MedOct 25, 2023
    risk 0.35cvss 5.3epss 0.01

    jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows attackers to bypass password brute-force protections by spoofing arbitrary IP addresses. By exploiting…

  • CVE-2023-42818MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.01

    JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force…

  • CVE-2023-35697MedJul 10, 2023
    risk 0.35cvss 5.3epss 0.01

    Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.

  • CVE-2021-27782MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

  • CVE-2022-44023MedOct 30, 2022
    risk 0.35cvss 5.3epss 0.01

    PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.

  • CVE-2022-44022MedOct 30, 2022
    risk 0.35cvss 5.3epss 0.01

    PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.

  • CVE-2022-24689MedJul 18, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being authenticated. The collected information includes the badge numbers that…

  • CVE-2021-33209MedNov 3, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.

  • CVE-2021-29842MedSep 16, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.

  • CVE-2021-33190MedJun 8, 2021
    risk 0.35cvss 5.3epss 0.03

    In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to…

  • CVE-2021-29023MedMay 17, 2021
    risk 0.35cvss 5.3epss 0.01

    InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

  • CVE-2021-1311MedJan 13, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host…

  • CVE-2020-8228MedOct 5, 2020
    risk 0.35cvss 5.3epss 0.02

    A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.

  • CVE-2020-8202MedJul 30, 2020
    risk 0.35cvss 5.3epss 0.01

    Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.

  • CVE-2020-1616MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.01

    Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remote attacker to perform multiple login…

  • CVE-2020-7057MedJan 14, 2020
    risk 0.35cvss 5.3epss 0.01

    Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5…

  • CVE-2019-1126MedJul 15, 2019
    risk 0.35cvss 5.3epss 0.05

    A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker…

  • CVE-2018-16703MedSep 7, 2018
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to…