CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
613 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 1 of 13
- CVE-1999-1152HIGHCVSS 7.5EG 7.51998-06-03
Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.
- CVE-1999-1324CRITICALCVSS 9.8EG 9.81999-12-31
VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct …
- CVE-2001-0395CRITICALCVSS 9.8EG 9.82001-07-02
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
- CVE-2001-1291CRITICALCVSS 9.8EG 9.82001-07-12
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
- CVE-2001-1339CRITICALCVSS 9.8EG 9.82001-05-24
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.
- CVE-2002-0628HIGHCVSS 7.5EG 7.52003-01-07
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
- CVE-2009-5140HIGHCVSS 8.8EG 8.82020-02-12
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to …
- CVE-2013-10004CRITICALCVSS 6.5EG 9.82022-05-24
A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Inco…
- CVE-2013-1895HIGHCVSS 7.5EG 7.52020-01-28
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.
- CVE-2013-2228HIGHCVSS 8.1EG 8.12019-12-03
SaltStack RSA Key Generation allows remote users to decrypt communications
- CVE-2013-2257HIGHCVSS 7.5EG 7.52019-11-04
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
- CVE-2013-4441CRITICALCVSS 9.8EG 9.82020-01-27
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.
- CVE-2014-2875MEDIUMCVSS 6.1EG 6.12020-02-06
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 we…
- CVE-2014-5414CRITICALCVSS 9.1EG 9.12016-10-05
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force…
- CVE-2015-20110HIGHCVSS 7.5EG 7.52023-10-31
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and …
- CVE-2016-9124CRITICALCVSS 9.8EG 9.82017-03-28
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to …
- CVE-2016-9361CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPo…
- CVE-2016-9366CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPo…
- CVE-2017-10604MEDIUMCVSS 5.3EG 5.32017-07-17
When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempting to log in as root with an incorrect password can trigger a lockout of the root account. When an SRX Series device i…
- CVE-2017-11187CRITICALCVSS 9.8EG 9.82017-07-12
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.
- CVE-2017-1197CRITICALCVSS 9.8EG 9.82017-06-15
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 123672.
- CVE-2017-12316HIGHCVSS 7.5EG 7.52017-11-16
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is…
- CVE-2017-14423HIGHCVSS 7.5EG 7.52017-09-13
htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does not prevent unauthenticated nonce-guessing attacks, which makes it easier for remote attackers to change the DNS configur…
- CVE-2017-15887CRITICALCVSS 9.8EG 9.82017-11-07
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
- CVE-2017-16900MEDIUMCVSS 5.5EG 5.52020-02-27
Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.
- CVE-2017-7673CRITICALCVSS 9.8EG 9.82017-07-17
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
- CVE-2017-7898CRITICALCVSS 9.8EG 9.82017-06-30
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BB…
- CVE-2017-7915CRITICALCVSS 9.8EG 9.82017-05-29
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150…
- CVE-2018-11082CRITICALCVSS 6.6EG 9.82018-10-05
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute …
- CVE-2018-12649CRITICALCVSS 9.8EG 9.82018-06-22
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only c…
- CVE-2018-12993CRITICALCVSS 9.8EG 9.82018-06-29
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.
- CVE-2018-1373CRITICALCVSS 7.5EG 9.82018-03-02
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 137773.
- CVE-2018-14657HIGHCVSS 8.1EG 8.12018-11-13
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
- CVE-2018-1475CRITICALCVSS 9.8EG 9.82018-04-27
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.
- CVE-2018-15759CRITICALCVSS 9.1EG 9.82018-11-19
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allo…
- CVE-2018-16703MEDIUMCVSS 5.3EG 5.32018-09-07
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt…
- CVE-2018-19021MEDIUMCVSS 6.5EG 6.52019-01-25
A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker to cause a denial of service.
- CVE-2018-19548CRITICALCVSS 9.8EG 9.82018-11-26
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password] parameters, which might make it easier for remote attackers to obtain access via a brute-force approach.
- CVE-2018-19879CRITICALCVSS 7.1EG 9.82019-03-28
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An a…
- CVE-2018-5469CRITICALCVSS 9.8EG 9.82018-03-06
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authenticatio…
- CVE-2019-0039HIGHCVSS 8.1EG 8.12019-04-10
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connection limit of the REST API may allow an attacker to brute-force passwords using advanced scripting techniques. Additionall…
- CVE-2019-1126MEDIUMCVSS 5.3EG 5.32019-07-15
A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted appl…
- CVE-2019-12941CRITICALCVSS 9.8EG 9.82019-10-14
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi S…
- CVE-2019-13166HIGHCVSS 7.5EG 7.52020-03-13
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
- CVE-2019-13394CRITICALCVSS 9.8EG 9.82020-03-13
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.
- CVE-2019-13918CRITICALCVSS 9.8EG 9.82019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to …
- CVE-2019-14299CRITICALCVSS 9.8EG 9.82020-03-13
Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.
- CVE-2019-14351HIGHCVSS 8.8EG 8.82019-07-28
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.
- CVE-2019-14951HIGHCVSS 7.5EG 7.52019-08-12
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-s…
- CVE-2019-15577MEDIUMCVSS 4.3EG 4.32019-12-18
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →