CWE-307
Improper Restriction of Excessive Authentication Attempts
Description
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (623)
page 3 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27152 | Cri | 0.64 | 9.8 | 0.01 | Oct 23, 2023 | DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication. | ||
| CVE-2023-36434 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2023 | Windows IIS Server Elevation of Privilege Vulnerability | ||
| CVE-2023-40834 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter. | ||
| CVE-2023-21709 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2023-32224 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2023 | D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts | ||
| CVE-2023-27746 | Cri | 0.64 | 9.8 | 0.02 | Apr 13, 2023 | BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted. | ||
| CVE-2023-24080 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack. | ||
| CVE-2022-40055 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2022 | An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page. | ||
| CVE-2022-33106 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2022 | WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over. | ||
| CVE-2022-2457 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2022 | A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts. | ||
| CVE-2022-35490 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2022 | Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling… | ||
| CVE-2022-22487 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2022 | An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques… | ||
| CVE-2022-22485 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability… | ||
| CVE-2022-31273 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie. | ||
| CVE-2021-43958 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing… | ||
| CVE-2022-26314 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an… | ||
| CVE-2022-22810 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2022 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)… | ||
| CVE-2021-43298 | Cri | 0.64 | 9.8 | 0.02 | Jan 25, 2022 | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's… | ||
| CVE-2020-21238 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2021 | An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks. | ||
| CVE-2020-21237 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2021 | An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks. |
- risk 0.64cvss 9.8epss 0.01
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
Windows IIS Server Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.01
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.
- risk 0.64cvss 9.8epss 0.02
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.01
D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
- risk 0.64cvss 9.8epss 0.02
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
- risk 0.64cvss 9.8epss 0.01
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
- risk 0.64cvss 9.8epss 0.01
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
- risk 0.64cvss 9.8epss 0.01
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
- risk 0.64cvss 9.8epss 0.01
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.
- risk 0.64cvss 9.8epss 0.01
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling…
- risk 0.64cvss 9.8epss 0.01
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques…
- risk 0.64cvss 9.8epss 0.01
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability…
- risk 0.64cvss 9.8epss 0.01
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
- risk 0.64cvss 9.8epss 0.01
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an…
- risk 0.64cvss 9.8epss 0.01
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)…
- risk 0.64cvss 9.8epss 0.02
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's…
- risk 0.64cvss 9.8epss 0.01
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
- risk 0.64cvss 9.8epss 0.01
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.