Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2022-10-12 CVE-2022-31228 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell Xtremio Management Server 6.3.0/6.3.38
Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability.
network
low complexity
dell CWE-307
critical
9.8
2022-10-12 CVE-2022-33106 Improper Restriction of Excessive Authentication Attempts vulnerability in Wijungle U250 Firmware
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
network
low complexity
wijungle CWE-307
critical
9.8
2022-09-28 CVE-2022-36781 Improper Restriction of Excessive Authentication Attempts vulnerability in Connectwise
WiseConnect - ScreenConnect Session Code Bypass.
network
low complexity
connectwise CWE-307
5.3
2022-07-05 CVE-2022-2321 Improper Restriction of Excessive Authentication Attempts vulnerability in Heroiclabs Nakama
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0.
network
low complexity
heroiclabs CWE-307
5.0
2022-06-30 CVE-2022-22496 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Server
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL.
low complexity
ibm CWE-307
3.3
2022-06-14 CVE-2022-31273 Improper Restriction of Excessive Authentication Attempts vulnerability in 17Ido Topidp3000 Topsec Operating System Tos3.3.005.665B.15Smpidp
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
network
low complexity
17ido CWE-307
5.0
2022-06-08 CVE-2022-28386 Improper Restriction of Excessive Authentication Attempts vulnerability in Verbatim products
An issue was discovered in certain Verbatim drives through 2022-03-31.
low complexity
verbatim CWE-307
4.6
2022-06-08 CVE-2022-28384 Improper Restriction of Excessive Authentication Attempts vulnerability in Verbatim products
An issue was discovered in certain Verbatim drives through 2022-03-31.
local
low complexity
verbatim CWE-307
5.5
2022-06-02 CVE-2022-30235 Improper Restriction of Excessive Authentication Attempts vulnerability in Schneider-Electric products
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses brute force.
network
low complexity
schneider-electric CWE-307
5.0
2022-06-02 CVE-2022-29084 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI.
network
low complexity
dell CWE-307
critical
10.0