CWE-307— Improper Restriction of Excessive Authentication Attempts
391 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 2 of 8
- CVE-2019-5217MEDIUMCVSS 4.6EG 4.62019-06-04
There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking the screen lock. Su…
- CVE-2019-5263MEDIUMCVSS 5.5EG 5.52019-11-29
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawei smartphone user backup information can…
- CVE-2019-5309MEDIUMCVSS 4.6EG 4.62019-11-29
Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lo…
- CVE-2019-5421CRITICALCVSS 9.8EG 9.82019-04-03
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/mod…
- CVE-2019-6524CRITICALCVSS 9.8EG 9.82019-03-05
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
- CVE-2020-10285CRITICALCVSS 9.8EG 9.82020-07-15
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
- CVE-2020-10849CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID …
- CVE-2020-10876HIGHCVSS 7.5EG 7.52020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excess…
- CVE-2020-11052HIGHCVSS 8.3EG 8.32020-05-07
In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protect…
- CVE-2020-11582HIGHCVSS 8.8EG 8.82020-04-06
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local c…
- CVE-2020-11650HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate …
- CVE-2020-12645CRITICALCVSS 9.8EG 9.82020-08-31
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
- CVE-2020-12752HIGHCVSS 7.5EG 7.52020-05-11
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 202…
- CVE-2020-13312MEDIUMCVSS 6.5EG 6.52020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.
- CVE-2020-13617HIGHCVSS 7.5EG 7.52020-08-26
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
- CVE-2020-13805CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
- CVE-2020-13835CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
- CVE-2020-13872HIGHCVSS 8.8EG 8.82020-06-09
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.
- CVE-2020-14484CRITICALCVSS 9.8EG 9.82020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.
- CVE-2020-14494CRITICALCVSS 9.8EG 9.82020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system a…
- CVE-2020-15367CRITICALCVSS 9.8EG 9.82020-07-07
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- CVE-2020-15770MEDIUMCVSS 5.5EG 5.52020-09-18
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
- CVE-2020-15786CRITICALCVSS 9.8EG 9.82020-09-09
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions …
- CVE-2020-15906CRITICALCVSS 9.8EG 9.82020-10-22
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
- CVE-2020-1616MEDIUMCVSS 5.3EG 5.32020-04-08
Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remo…
- CVE-2020-18698CRITICALCVSS 9.8EG 9.82021-08-16
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
- CVE-2020-21237CRITICALCVSS 9.8EG 9.82021-12-27
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
- CVE-2020-21238CRITICALCVSS 9.8EG 9.82021-12-27
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
- CVE-2020-23283HIGHCVSS 7.5EG 7.52021-07-21
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.
- CVE-2020-24007CRITICALCVSS 9.8EG 9.82020-08-26
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- CVE-2020-25196CRITICALCVSS 9.8EG 9.82020-12-23
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.
- CVE-2020-25827HIGHCVSS 7.5EG 7.52020-09-27
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a sin…
- CVE-2020-26556HIGHCVSS 7.5EG 7.52021-05-24
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authen…
- CVE-2020-27423HIGHCVSS 7.5EG 7.52020-11-16
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
- CVE-2020-27747MEDIUMCVSS 6.8EG 6.82020-10-29
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportun…
- CVE-2020-28206MEDIUMCVSS 6.5EG 6.52020-12-02
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enu…
- CVE-2020-28212CRITICALCVSS 9.8EG 9.82020-11-19
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force at…
- CVE-2020-29042LOWCVSS 3.7EG 3.72020-11-26
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
- CVE-2020-29136MEDIUMCVSS 6.5EG 6.52020-11-27
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
- CVE-2020-35565CRITICALCVSS 9.8EG 9.82021-02-16
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
- CVE-2020-35585HIGHCVSS 7.5EG 7.52020-12-23
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.
- CVE-2020-35586HIGHCVSS 7.5EG 7.52020-12-23
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it mi…
- CVE-2020-35590CRITICALCVSS 9.8EG 9.82020-12-21
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arb…
- CVE-2020-37228CRITICALCVSS 9.8EG 9.82026-05-16
iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login e…
- CVE-2020-4193CRITICALCVSS 9.8EG 9.82020-06-04
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
- CVE-2020-4232HIGHCVSS 7.5EG 7.52020-05-28
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.
- CVE-2020-4400HIGHCVSS 7.5EG 7.52020-07-22
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.
- CVE-2020-4567CRITICALCVSS 9.8EG 9.82020-07-29
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.
- CVE-2020-4891MEDIUMCVSS 5.5EG 5.52021-03-16
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.
- CVE-2020-5141MEDIUMCVSS 6.5EG 6.52020-10-12
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.1…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →