VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 9 of 32
  • CVE-2009-5140HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.01

    The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

  • CVE-2019-18985CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks brute force protection for the 2FA token.

  • CVE-2019-3746HigSep 27, 2019
    risk 0.57cvss 8.8epss 0.02

    Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attack in order to gain access to the system.

  • CVE-2019-14351HigJul 28, 2019
    risk 0.57cvss 8.8epss 0.01

    EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.

  • CVE-2016-10321CriApr 10, 2017
    risk 0.57cvss 9.8epss 0.03

    web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.

  • CVE-2025-2417HigSep 4, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass. This issue affects e-Mutabakat: from 2.02.06 before v2.02.06.

  • CVE-2025-2411HigSep 4, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass. This issue affects TaskPano: from s1.06.04 before v1.06.06.

  • CVE-2025-2416HigSep 3, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass. This issue affects LimonDesk: from s1.02.14 before v1.02.17.

  • CVE-2025-2415HigSep 3, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass. This issue affects MyRezzta: from s2.03.01 before v2.05.01.

  • CVE-2025-2413HigSep 2, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass. This issue affects ProKuafor: from s1.02.08 before v1.02.08.

  • CVE-2025-2414HigSep 2, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass. This issue affects OctoCloud: from s1.09.03 before v1.11.01.

  • CVE-2025-2412HigSep 1, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.05.07 before v1.05.12.

  • CVE-2022-45790HigJan 22, 2024
    risk 0.56cvss 8.6epss 0.01

    The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

  • CVE-2023-40706HigAug 24, 2023
    risk 0.56cvss 8.6epss 0.01

    There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.

  • CVE-2022-32515HigJan 30, 2023
    risk 0.56cvss 8.6epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™…

  • CVE-2022-30235HigJun 2, 2022
    risk 0.56cvss 8.6epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses brute force. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2023-3548HigJul 25, 2023
    risk 0.54cvss 8.3epss 0.01

    An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

  • CVE-2021-36750HigDec 22, 2021
    risk 0.54cvss 8.1epss 0.14

    ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

  • CVE-2026-22278HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.00

    Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2025-42615HigDec 8, 2025
    risk 0.53cvss epss 0.00

    In affected versions, vulnerability-lookup did not track or limit failed One-Time Password (OTP) attempts during Two-Factor Authentication (2FA) verification. An attacker who already knew or guessed a valid username and password could submit an arbitrary number of OTP codes…