CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
689 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 2 of 14
- CVE-2023-6272CRITICALCVSS 9.8EG 9.82023-12-18
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
- CVE-2023-6756CRITICALCVSS 9.8EG 9.82023-12-13
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive auth…
- CVE-2023-49443CRITICALCVSS 9.8EG 9.82023-12-08
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.
- CVE-2023-35039CRITICALCVSS 9.8EG 9.82023-12-07
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress RES…
- CVE-2023-24051CRITICALCVSS 9.8EG 9.82023-12-04
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.
- CVE-2023-48028CRITICALCVSS 9.8EG 9.82023-11-18
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
- CVE-2023-2675CRITICALCVSS 9.8EG 9.82023-11-07
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
- CVE-2023-41350CRITICALCVSS 9.8EG 9.82023-11-03
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very …
- CVE-2023-5754CRITICALCVSS 9.8EG 9.82023-10-26
Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
- CVE-2023-42769CRITICALCVSS 9.8EG 9.82023-10-26
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
- CVE-2023-37635CRITICALCVSS 9.8EG 9.82023-10-23
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
- CVE-2023-27152CRITICALCVSS 9.8EG 9.82023-10-23
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
- CVE-2023-36434CRITICALCVSS 9.8EG 9.82023-10-10
Windows IIS Server Elevation of Privilege Vulnerability
- CVE-2023-42818CRITICALCVSS 9.8EG 9.82023-09-27
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a discl…
- CVE-2023-40834CRITICALCVSS 9.8EG 9.82023-09-12
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.
- CVE-2023-21709CRITICALCVSS 9.8EG 9.82023-08-08
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2023-32224CRITICALCVSS 9.8EG 9.82023-06-28
D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
- CVE-2023-3173CRITICALCVSS 9.8EG 9.82023-06-09
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
- CVE-2023-2531CRITICALCVSS 9.8EG 9.82023-05-05
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
- CVE-2022-2525CRITICALCVSS 9.8EG 9.82023-04-15
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
- CVE-2023-27746CRITICALCVSS 9.8EG 9.82023-04-13
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
- CVE-2023-1665CRITICALCVSS 9.8EG 9.82023-03-27
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
- CVE-2023-27100CRITICALCVSS 9.8EG 9.82023-03-22
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web reque…
- CVE-2023-24080CRITICALCVSS 9.8EG 9.82023-02-21
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
- CVE-2022-2650CRITICALCVSS 9.8EG 9.82022-11-24
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
- CVE-2022-2166CRITICALCVSS 9.8EG 9.82022-11-16
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
- CVE-2022-3741CRITICALCVSS 9.8EG 9.82022-10-28
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be…
- CVE-2022-40055CRITICALCVSS 9.8EG 9.82022-10-17
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
- CVE-2022-33106CRITICALCVSS 9.8EG 9.82022-10-12
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
- CVE-2022-2457CRITICALCVSS 9.8EG 9.82022-08-10
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.
- CVE-2022-35490CRITICALCVSS 9.8EG 9.82022-08-08
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker mig…
- CVE-2022-2321CRITICALCVSS 9.8EG 9.82022-07-05
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.
- CVE-2022-22487CRITICALCVSS 9.8EG 9.82022-06-30
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vu…
- CVE-2022-22485CRITICALCVSS 9.8EG 9.82022-06-17
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attack…
- CVE-2022-31273CRITICALCVSS 9.8EG 9.82022-06-14
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
- CVE-2021-43958CRITICALCVSS 9.8EG 9.82022-03-16
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required so…
- CVE-2022-26314CRITICALCVSS 9.8EG 9.82022-03-08
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an in…
- CVE-2022-22810CRITICALCVSS 9.8EG 9.82022-02-09
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior),…
- CVE-2021-43298CRITICALCVSS 9.8EG 9.82022-01-25
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte…
- CVE-2020-21238CRITICALCVSS 9.8EG 9.82021-12-27
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
- CVE-2020-21237CRITICALCVSS 9.8EG 9.82021-12-27
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
- CVE-2021-37934CRITICALCVSS 9.8EG 9.82021-12-10
Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force passwor…
- CVE-2021-41435CRITICALCVSS 9.8EG 9.82021-11-19
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-A…
- CVE-2021-28911CRITICALCVSS 9.8EG 9.82021-09-09
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-calculated in a brute…
- CVE-2021-28909CRITICALCVSS 9.8EG 9.82021-09-09
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The password could be weak and default username is known as 'adm…
- CVE-2020-18698CRITICALCVSS 9.8EG 9.82021-08-16
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
- CVE-2021-32522CRITICALCVSS 9.8EG 9.82021-07-07
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN …
- CVE-2021-22915CRITICALCVSS 9.8EG 9.82021-06-11
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such…
- CVE-2021-22737CRITICALCVSS 9.8EG 9.82021-05-26
Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.
- CVE-2021-31646CRITICALCVSS 9.8EG 9.82021-04-26
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP unique…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →