VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 3 of 32
  • CVE-2023-27152CriOct 23, 2023
    risk 0.64cvss 9.8epss 0.01

    DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

  • CVE-2023-36434CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows IIS Server Elevation of Privilege Vulnerability

  • CVE-2023-40834CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

  • CVE-2023-21709CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2023-32224CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts

  • CVE-2023-27746CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.02

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.

  • CVE-2023-24080CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.

  • CVE-2022-40055CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

  • CVE-2022-33106CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

  • CVE-2022-2457CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

  • CVE-2022-35490CriAug 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling…

  • CVE-2022-22487CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques…

  • CVE-2022-22485CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability…

  • CVE-2022-31273CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.

  • CVE-2021-43958CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing…

  • CVE-2022-26314CriMar 8, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an…

  • CVE-2022-22810CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)…

  • CVE-2021-43298CriJan 25, 2022
    risk 0.64cvss 9.8epss 0.02

    The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's…

  • CVE-2020-21238CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.

  • CVE-2020-21237CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.