CWE · MITRE source
CWE-307Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Last updated: 09 May 2026 03:25 UTC
NIST 800-53 r5 controls that address this weakness (2)AI
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
AC-7 | Unsuccessful Logon Attempts | AC | This control directly enforces limits on consecutive invalid logon attempts and automatic response (e.g., lockout) to prevent brute-force exploitation of authentication mechanisms. |
IA-10 | Adaptive Authentication | IA | Specific conditions can include excessive failed attempts, triggering stronger authentication that restricts brute-force exploitation. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2020-15906 | 7.2 | 9.8 | 0.8702 | 2020-10-22 |
CVE-2019-17240 | 6.9 | 9.8 | 0.8263 | 2019-10-06 |
CVE-2023-22960 | 5.2 | 7.5 | 0.6125 | 2023-01-23 |
CVE-2024-39225 | 4.6 | 9.8 | 0.4453 | 2024-08-06 |
CVE-2020-35590 | 4.5 | 9.8 | 0.4285 | 2020-12-21 |
CVE-2001-1339 | 3.4 | 9.8 | 0.2428 | 2001-05-24 |
CVE-2021-27514 | 2.8 | 9.8 | 0.1367 | 2021-02-22 |
CVE-2021-36750 | 2.8 | 8.1 | 0.1970 | 2021-12-22 |
CVE-2024-41276 | 2.8 | 9.8 | 0.1356 | 2024-10-01 |
CVE-2019-17525 | 2.7 | 8.8 | 0.1620 | 2020-04-21 |
CVE-2023-27746 | 2.6 | 9.8 | 0.1011 | 2023-04-13 |
CVE-2023-37635 | 2.5 | 9.8 | 0.0823 | 2023-10-23 |
CVE-2001-1291 | 2.4 | 9.8 | 0.0724 | 2001-07-12 |
CVE-2020-27423 | 2.4 | 7.5 | 0.1497 | 2020-11-16 |
CVE-2014-5414 | 2.2 | 9.1 | 0.0594 | 2016-10-05 |
CVE-2020-11650 | 2.2 | 7.5 | 0.1192 | 2020-04-08 |
CVE-2022-29056 | 2.2 | 3.7 | 0.2430 | 2023-03-09 |
CVE-2023-27100 | 2.2 | 9.8 | 0.0350 | 2023-03-22 |
CVE-2023-21709 | 2.2 | 9.8 | 0.0319 | 2023-08-08 |
CVE-2019-3766 | 2.1 | 9.8 | 0.0202 | 2019-09-27 |
CVE-2020-15367 | 2.1 | 9.8 | 0.0265 | 2020-07-07 |
CVE-2020-24007 | 2.1 | 9.8 | 0.0185 | 2020-08-26 |
CVE-2021-28909 | 2.1 | 9.8 | 0.0176 | 2021-09-09 |
CVE-2021-28911 | 2.1 | 9.8 | 0.0233 | 2021-09-09 |
CVE-2021-41435 | 2.1 | 9.8 | 0.0250 | 2021-11-19 |