Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2022-06-17 CVE-2022-22485 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Operations Center
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server.
network
low complexity
ibm CWE-307
critical
9.8
2022-06-14 CVE-2022-31273 Improper Restriction of Excessive Authentication Attempts vulnerability in 17Ido Topidp3000 Topsec Operating System Tos3.3.005.665B.15Smpidp
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
network
low complexity
17ido CWE-307
critical
9.8
2022-06-08 CVE-2022-28386 Improper Restriction of Excessive Authentication Attempts vulnerability in Verbatim products
An issue was discovered in certain Verbatim drives through 2022-03-31.
low complexity
verbatim CWE-307
4.6
2022-06-08 CVE-2022-28384 Improper Restriction of Excessive Authentication Attempts vulnerability in Verbatim products
An issue was discovered in certain Verbatim drives through 2022-03-31.
local
low complexity
verbatim CWE-307
5.5
2022-06-02 CVE-2022-30235 Improper Restriction of Excessive Authentication Attempts vulnerability in Schneider-Electric products
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses brute force.
network
low complexity
schneider-electric CWE-307
critical
9.8
2022-06-02 CVE-2022-29084 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI.
network
low complexity
dell CWE-307
critical
9.8
2022-05-24 CVE-2013-10004 Improper Restriction of Excessive Authentication Attempts vulnerability in Telecomsoftware Samwin Agent and Samwin Contact Center
A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1.
network
low complexity
telecomsoftware CWE-307
critical
9.8
2022-05-20 CVE-2022-24044 Improper Restriction of Excessive Authentication Attempts vulnerability in Siemens products
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).
network
low complexity
siemens CWE-307
7.5
2022-04-20 CVE-2022-26519 Improper Restriction of Excessive Authentication Attempts vulnerability in Carrier Hills Comnav Firmware 300219
There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Version 3002-19 interface, which allows local attackers to brute-force credentials.
local
low complexity
carrier CWE-307
5.5
2022-04-12 CVE-2022-22561 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts.
network
low complexity
dell CWE-307
critical
9.8