CWE-307— Improper Restriction of Excessive Authentication Attempts
391 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 1 of 8
- CVE-2009-5140HIGHCVSS 8.8EG 8.82020-02-12
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to …
- CVE-2013-10004MEDIUMCVSS 6.5EG 9.82022-05-24
A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Inco…
- CVE-2013-1895HIGHCVSS 7.5EG 7.52020-01-28
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.
- CVE-2013-2228HIGHCVSS 8.1EG 8.12019-12-03
SaltStack RSA Key Generation allows remote users to decrypt communications
- CVE-2013-2257HIGHCVSS 7.5EG 7.52019-11-04
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
- CVE-2013-4441CRITICALCVSS 9.8EG 9.82020-01-27
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.
- CVE-2014-2875MEDIUMCVSS 6.1EG 6.12020-02-06
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 we…
- CVE-2015-20110HIGHCVSS 7.5EG 7.52023-10-31
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and …
- CVE-2017-16900MEDIUMCVSS 5.5EG 5.52020-02-27
Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.
- CVE-2018-11082MEDIUMCVSS 6.62018-10-05
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute …
- CVE-2018-12649CRITICALCVSS 9.82018-06-22
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only c…
- CVE-2018-12993CRITICALCVSS 9.82018-06-29
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.
- CVE-2018-1373HIGHCVSS 7.52018-03-02
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 137773.
- CVE-2018-14657HIGHCVSS 8.12018-11-13
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
- CVE-2018-1475CRITICALCVSS 9.82018-04-27
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.
- CVE-2018-15759CRITICALCVSS 9.12018-11-19
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allo…
- CVE-2018-16703MEDIUMCVSS 5.32018-09-07
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt…
- CVE-2018-19021MEDIUMCVSS 6.52019-01-25
A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker to cause a denial of service.
- CVE-2018-19548CRITICALCVSS 9.82018-11-26
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password] parameters, which might make it easier for remote attackers to obtain access via a brute-force approach.
- CVE-2018-19879HIGHCVSS 7.1EG 9.82019-03-28
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An a…
- CVE-2018-5469CRITICALCVSS 9.82018-03-06
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authenticatio…
- CVE-2019-0039HIGHCVSS 8.1EG 8.12019-04-10
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting techniques. Additionall…
- CVE-2019-1126MEDIUMCVSS 5.3EG 5.32019-07-15
A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted appl…
- CVE-2019-12941CRITICALCVSS 9.8EG 9.82019-10-14
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi S…
- CVE-2019-13166HIGHCVSS 7.5EG 7.52020-03-13
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
- CVE-2019-13394CRITICALCVSS 9.8EG 9.82020-03-13
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.
- CVE-2019-13918CRITICALCVSS 9.8EG 9.82019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to …
- CVE-2019-14299CRITICALCVSS 9.8EG 9.82020-03-13
Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.
- CVE-2019-14351HIGHCVSS 8.8EG 8.82019-07-28
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.
- CVE-2019-14951HIGHCVSS 7.5EG 7.52019-08-12
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-s…
- CVE-2019-15577MEDIUMCVSS 4.3EG 4.32019-12-18
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
- CVE-2019-16670CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.
- CVE-2019-17215CRITICALCVSS 9.8EG 9.82019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the d…
- CVE-2019-17240CRITICALCVSS 9.8EG 9.82019-10-06
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
- CVE-2019-17525HIGHCVSS 8.8EG 8.82020-04-21
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
- CVE-2019-18235CRITICALCVSS 9.8EG 9.82021-03-17
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.
- CVE-2019-18261CRITICALCVSS 9.8EG 9.82019-12-16
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time f…
- CVE-2019-18917MEDIUMCVSS 6.5EG 6.52020-03-16
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.
- CVE-2019-18985CRITICALCVSS 9.8EG 9.82019-11-15
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
- CVE-2019-18986HIGHCVSS 7.5EG 7.52019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
- CVE-2019-20031CRITICALCVSS 9.1EG 9.12020-07-29
NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.
- CVE-2019-20881HIGHCVSS 7.3EG 7.32020-06-19
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
- CVE-2019-3746HIGHCVSS 8.8EG 8.82019-09-27
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attac…
- CVE-2019-3766CRITICALCVSS 9.8EG 9.82019-09-27
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targe…
- CVE-2019-4068HIGHCVSS 7.5EG 7.52019-06-07
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013.
- CVE-2019-4310HIGHCVSS 7.5EG 7.52019-08-20
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036.
- CVE-2019-4336CRITICALCVSS 9.8EG 9.82019-07-01
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.
- CVE-2019-4393CRITICALCVSS 9.8EG 9.82020-04-07
HCL AppScan Standard is vulnerable to excessive authorization attempts
- CVE-2019-4520HIGHCVSS 7.5EG 7.52019-10-02
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.
- CVE-2019-5035CRITICALCVSS 9.0EG 9.02019-08-20
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater We…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →