VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 5 of 32
  • CVE-2020-14494CriJul 20, 2020
    risk 0.64cvss 9.8epss 0.01

    OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number…

  • CVE-2020-14484CriJul 20, 2020
    risk 0.64cvss 9.8epss 0.01

    OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.

  • CVE-2020-10285CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.01

    The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.

  • CVE-2020-15367CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

  • CVE-2020-7508CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.01

    A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.

  • CVE-2020-13835CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).

  • CVE-2020-13805CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.

  • CVE-2020-4193CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.

  • CVE-2020-8790CriMay 4, 2020
    risk 0.64cvss 9.8epss 0.02

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a…

  • CVE-2019-4393CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard is vulnerable to excessive authorization attempts

  • CVE-2020-6852CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.02

    CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.

  • CVE-2020-10849CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-14575 (January 2020).

  • CVE-2019-14299CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.01

    Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.

  • CVE-2013-4441CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

  • CVE-2020-7995CriJan 26, 2020
    risk 0.64cvss 9.8epss 0.05

    The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

  • CVE-2019-18261CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.01

    In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to…

  • CVE-2019-16670CriDec 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.

  • CVE-2019-12941CriOct 14, 2019
    risk 0.64cvss 9.8epss 0.02

    AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi SSID are derived from the same hash…

  • CVE-2019-17215CriOct 6, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the device.

  • CVE-2019-3766CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.02

    Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targeted accounts.