Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2020-10-12 CVE-2020-5141 Improper Restriction of Excessive Authentication Attempts vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service.
network
low complexity
sonicwall CWE-307
6.4
2020-10-05 CVE-2020-6875 Improper Restriction of Excessive Authentication Attempts vulnerability in ZTE Zxone 19700 Snpe Firmware Zxone8700V1.40R2B13Snpe
A ZTE product is impacted by the improper access control vulnerability.
network
low complexity
zte CWE-307
5.0
2020-10-05 CVE-2020-8228 Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
network
low complexity
nextcloud opensuse CWE-307
5.0
2020-09-27 CVE-2020-25827 Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4.
network
low complexity
mediawiki fedoraproject CWE-307
7.5
2020-09-18 CVE-2020-15770 Improper Restriction of Excessive Authentication Attempts vulnerability in Gradle Enterprise 2018.5
An issue was discovered in Gradle Enterprise 2018.5.
local
low complexity
gradle CWE-307
5.5
2020-09-09 CVE-2020-15786 Improper Restriction of Excessive Authentication Attempts vulnerability in Siemens products
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl.
network
low complexity
siemens CWE-307
5.0
2020-08-31 CVE-2020-7525 Improper Restriction of Excessive Authentication Attempts vulnerability in Schneider-Electric Spacelynk Firmware and Wiser FOR KNX Firmware
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.
network
low complexity
schneider-electric CWE-307
5.0
2020-08-26 CVE-2020-13617 Improper Restriction of Excessive Authentication Attempts vulnerability in Mitel products
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
network
low complexity
mitel CWE-307
5.0
2020-08-26 CVE-2020-24007 Improper Restriction of Excessive Authentication Attempts vulnerability in Umanni Human Resources 1.0
Umanni RH 1.0 does not limit the number of authentication attempts.
network
low complexity
umanni CWE-307
7.5
2020-07-30 CVE-2020-8202 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Preferred Providers 1.6.0
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
network
low complexity
nextcloud CWE-307
5.0