CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
689 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 3 of 14
- CVE-2019-18235CRITICALCVSS 9.8EG 9.82021-03-17
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force password attack.
- CVE-2021-25309CRITICALCVSS 9.8EG 9.82021-03-02
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) al…
- CVE-2021-27514CRITICALCVSS 9.8EG 9.82021-02-22
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
- CVE-2020-35565CRITICALCVSS 9.8EG 9.82021-02-16
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
- CVE-2020-25196CRITICALCVSS 9.8EG 9.82020-12-23
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.
- CVE-2020-35590CRITICALCVSS 9.8EG 9.82020-12-21
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arb…
- CVE-2020-28212CRITICALCVSS 9.8EG 9.82020-11-19
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force at…
- CVE-2020-15906CRITICALCVSS 9.8EG 9.82020-10-22
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
- CVE-2020-6875CRITICALCVSS 9.8EG 9.82020-10-05
A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access right through brute-force attacks. This aff…
- CVE-2020-15786CRITICALCVSS 9.8EG 9.82020-09-09
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions …
- CVE-2020-12645CRITICALCVSS 9.8EG 9.82020-08-31
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
- CVE-2020-24007CRITICALCVSS 9.8EG 9.82020-08-26
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- CVE-2020-4567CRITICALCVSS 9.8EG 9.82020-07-29
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.
- CVE-2020-14494CRITICALCVSS 9.8EG 9.82020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system a…
- CVE-2020-14484CRITICALCVSS 9.8EG 9.82020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.
- CVE-2020-10285CRITICALCVSS 9.8EG 9.82020-07-15
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
- CVE-2020-15367CRITICALCVSS 9.8EG 9.82020-07-07
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- CVE-2020-7508CRITICALCVSS 9.8EG 9.82020-06-16
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.
- CVE-2020-13835CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
- CVE-2020-13805CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
- CVE-2020-4193CRITICALCVSS 9.8EG 9.82020-06-04
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
- CVE-2020-8790CRITICALCVSS 9.8EG 9.82020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover use…
- CVE-2019-4393CRITICALCVSS 9.8EG 9.82020-04-07
HCL AppScan Standard is vulnerable to excessive authorization attempts
- CVE-2020-6852CRITICALCVSS 9.8EG 9.82020-04-02
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
- CVE-2020-10849CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID …
- CVE-2019-14299CRITICALCVSS 9.8EG 9.82020-03-13
Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.
- CVE-2019-13394CRITICALCVSS 9.8EG 9.82020-03-13
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.
- CVE-2013-4441CRITICALCVSS 9.8EG 9.82020-01-27
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.
- CVE-2020-7995CRITICALCVSS 9.8EG 9.82020-01-26
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
- CVE-2019-18261CRITICALCVSS 9.8EG 9.82019-12-16
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time f…
- CVE-2019-16670CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.
- CVE-2019-18985CRITICALCVSS 9.8EG 9.82019-11-15
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
- CVE-2019-12941CRITICALCVSS 9.8EG 9.82019-10-14
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi S…
- CVE-2019-17240CRITICALCVSS 9.8EG 9.82019-10-06
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
- CVE-2019-17215CRITICALCVSS 9.8EG 9.82019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the d…
- CVE-2019-3766CRITICALCVSS 9.8EG 9.82019-09-27
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targe…
- CVE-2019-13918CRITICALCVSS 9.8EG 9.82019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to …
- CVE-2019-4336CRITICALCVSS 9.8EG 9.82019-07-01
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.
- CVE-2019-5421CRITICALCVSS 9.8EG 9.82019-04-03
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/mod…
- CVE-2019-6524CRITICALCVSS 9.8EG 9.82019-03-05
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
- CVE-2018-19548CRITICALCVSS 9.8EG 9.82018-11-26
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password] parameters, which might make it easier for remote attackers to obtain access via a brute-force approach.
- CVE-2018-12993CRITICALCVSS 9.8EG 9.82018-06-29
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.
- CVE-2018-12649CRITICALCVSS 9.8EG 9.82018-06-22
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only c…
- CVE-2018-1475CRITICALCVSS 9.8EG 9.82018-04-27
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.
- CVE-2018-5469CRITICALCVSS 9.8EG 9.82018-03-06
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authenticatio…
- CVE-2017-15887CRITICALCVSS 9.8EG 9.82017-11-07
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
- CVE-2017-7673CRITICALCVSS 9.8EG 9.82017-07-17
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
- CVE-2017-11187CRITICALCVSS 9.8EG 9.82017-07-12
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.
- CVE-2017-7898CRITICALCVSS 9.8EG 9.82017-06-30
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BB…
- CVE-2017-1197CRITICALCVSS 9.8EG 9.82017-06-15
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 123672.
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →