CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
643 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 2 of 13
- CVE-2019-16670CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.
- CVE-2019-17215CRITICALCVSS 9.8EG 9.82019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the d…
- CVE-2019-17240CRITICALCVSS 9.8EG 9.82019-10-06
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
- CVE-2019-17525HIGHCVSS 8.8EG 8.82020-04-21
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
- CVE-2019-18235CRITICALCVSS 9.8EG 9.82021-03-17
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.
- CVE-2019-18261CRITICALCVSS 9.8EG 9.82019-12-16
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time f…
- CVE-2019-18917MEDIUMCVSS 6.5EG 6.52020-03-16
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.
- CVE-2019-18985CRITICALCVSS 9.8EG 9.82019-11-15
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
- CVE-2019-18986HIGHCVSS 7.5EG 7.52019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
- CVE-2019-20031CRITICALCVSS 9.1EG 9.12020-07-29
NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.
- CVE-2019-20881HIGHCVSS 7.3EG 7.32020-06-19
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
- CVE-2019-3746HIGHCVSS 8.8EG 8.82019-09-27
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API. An authenticated remote user may exploit this vulnerability to launch a brute-force authentication attac…
- CVE-2019-3766CRITICALCVSS 9.8EG 9.82019-09-27
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targe…
- CVE-2019-4068HIGHCVSS 7.5EG 7.52019-06-07
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013.
- CVE-2019-4310HIGHCVSS 7.5EG 7.52019-08-20
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036.
- CVE-2019-4336CRITICALCVSS 9.8EG 9.82019-07-01
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.
- CVE-2019-4393CRITICALCVSS 9.8EG 9.82020-04-07
HCL AppScan Standard is vulnerable to excessive authorization attempts
- CVE-2019-4520HIGHCVSS 7.5EG 7.52019-10-02
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.
- CVE-2019-5035CRITICALCVSS 9.0EG 9.02019-08-20
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater We…
- CVE-2019-5217MEDIUMCVSS 4.6EG 4.62019-06-04
There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking the screen lock. Su…
- CVE-2019-5263MEDIUMCVSS 5.5EG 5.52019-11-29
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawei smartphone user backup information can…
- CVE-2019-5309MEDIUMCVSS 4.6EG 4.62019-11-29
Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lo…
- CVE-2019-5421CRITICALCVSS 9.8EG 9.82019-04-03
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/mod…
- CVE-2019-6524CRITICALCVSS 9.8EG 9.82019-03-05
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
- CVE-2020-10285CRITICALCVSS 9.8EG 9.82020-07-15
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
- CVE-2020-10849CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID …
- CVE-2020-10876HIGHCVSS 7.5EG 7.52020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excess…
- CVE-2020-11052HIGHCVSS 8.3EG 8.32020-05-07
In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protect…
- CVE-2020-11582HIGHCVSS 8.8EG 8.82020-04-06
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local c…
- CVE-2020-11650HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate …
- CVE-2020-12645CRITICALCVSS 9.8EG 9.82020-08-31
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
- CVE-2020-12752HIGHCVSS 7.5EG 7.52020-05-11
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 202…
- CVE-2020-13312MEDIUMCVSS 6.5EG 6.52020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.
- CVE-2020-13617HIGHCVSS 7.5EG 7.52020-08-26
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
- CVE-2020-13805CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
- CVE-2020-13835CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
- CVE-2020-13872HIGHCVSS 8.8EG 8.82020-06-09
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.
- CVE-2020-14484CRITICALCVSS 9.8EG 9.82020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.
- CVE-2020-14494CRITICALCVSS 9.8EG 9.82020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system a…
- CVE-2020-15367CRITICALCVSS 9.8EG 9.82020-07-07
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- CVE-2020-15770MEDIUMCVSS 5.5EG 5.52020-09-18
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
- CVE-2020-15786CRITICALCVSS 9.8EG 9.82020-09-09
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions …
- CVE-2020-15906CRITICALCVSS 9.8EG 9.82020-10-22
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
- CVE-2020-1616MEDIUMCVSS 5.3EG 5.32020-04-08
Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP) devices allows an unauthenticated, remo…
- CVE-2020-18698CRITICALCVSS 9.8EG 9.82021-08-16
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
- CVE-2020-21237CRITICALCVSS 9.8EG 9.82021-12-27
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
- CVE-2020-21238CRITICALCVSS 9.8EG 9.82021-12-27
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
- CVE-2020-23283HIGHCVSS 7.5EG 7.52021-07-21
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.
- CVE-2020-24007CRITICALCVSS 9.8EG 9.82020-08-26
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- CVE-2020-25196CRITICALCVSS 9.8EG 9.82020-12-23
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →