Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2022-08-02 CVE-2022-35925 Improper Restriction of Excessive Authentication Attempts vulnerability in Joinbookwyrm Bookwyrm
BookWyrm is a social network for tracking reading.
network
low complexity
joinbookwyrm CWE-307
critical
9.8
2022-07-28 CVE-2021-22640 Improper Restriction of Excessive Authentication Attempts vulnerability in Ovarro products
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
network
low complexity
ovarro CWE-307
critical
9.8
2022-07-21 CVE-2022-31234 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI.
network
low complexity
dell CWE-307
critical
9.8
2022-07-18 CVE-2022-24689 Improper Restriction of Excessive Authentication Attempts vulnerability in DSK Dsknet 2.16.136.0/2.17.136.5
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5.
network
low complexity
dsk CWE-307
5.3
2022-07-14 CVE-2022-22452 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
7.5
2022-06-30 CVE-2022-22487 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Server
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID.
network
low complexity
ibm CWE-307
critical
9.8
2022-06-30 CVE-2022-22496 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Server
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL.
low complexity
ibm CWE-307
6.5
2022-06-17 CVE-2022-22485 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Operations Center
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server.
network
low complexity
ibm CWE-307
critical
9.8
2022-06-14 CVE-2022-31273 Improper Restriction of Excessive Authentication Attempts vulnerability in 17Ido Topidp3000 Topsec Operating System Tos3.3.005.665B.15Smpidp
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
network
low complexity
17ido CWE-307
critical
9.8
2022-06-08 CVE-2022-28386 Improper Restriction of Excessive Authentication Attempts vulnerability in Verbatim products
An issue was discovered in certain Verbatim drives through 2022-03-31.
low complexity
verbatim CWE-307
4.6