Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-42480 Improper Restriction of Excessive Authentication Attempts vulnerability in SAP Netweaver Application Server Java 7.50
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
network
low complexity
sap CWE-307
5.3
2023-11-08 CVE-2023-41270 Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Ue40D7000 Firmware Tgapdeuc1033.2
Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.
low complexity
samsung CWE-307
4.3
2023-11-07 CVE-2023-2675 Improper Restriction of Excessive Authentication Attempts vulnerability in Linagora Twake
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
network
low complexity
linagora CWE-307
critical
9.8
2023-11-06 CVE-2023-4625 Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishielectric products
Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/iQ-R Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from logging into the Web server function for a certain period after the attacker has attempted to log in illegally by continuously attempting unauthorized login to the Web server function.
network
low complexity
mitsubishielectric CWE-307
5.3
2023-11-03 CVE-2023-41350 Improper Restriction of Excessive Authentication Attempts vulnerability in Nokia G-040W-Q Firmware G040Wqr201207
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts.
network
low complexity
nokia CWE-307
critical
9.8
2023-10-31 CVE-2023-37832 Improper Restriction of Excessive Authentication Attempts vulnerability in Elenos Etg150 Firmware 3.12
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.
network
low complexity
elenos CWE-307
7.5
2023-10-31 CVE-2015-20110 Improper Restriction of Excessive Authentication Attempts vulnerability in Jhipster
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different.
network
low complexity
jhipster CWE-307
7.5
2023-10-26 CVE-2023-5754 Improper Restriction of Excessive Authentication Attempts vulnerability in Sielco products
Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
network
low complexity
sielco CWE-307
critical
9.8
2023-10-26 CVE-2023-42769 Improper Restriction of Excessive Authentication Attempts vulnerability in Sielco products
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
network
low complexity
sielco CWE-307
critical
9.8
2023-10-25 CVE-2023-46123 Improper Restriction of Excessive Authentication Attempts vulnerability in Fit2Cloud Jumpserver
jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications.
network
low complexity
fit2cloud CWE-307
5.3