CWE-645: Overly Restrictive Account Lockout Mechanism
The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.
7 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-37028 — BIG-IP Next Central Manager vulnerability
- CVE-2026-53982 — Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
- CVE-2025-31947 — Repeated LDAP login failures can lock an LDAP account
- CVE-2026-25907 — Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unau
- CVE-2025-5241 — Denial-of-Service Vulnerability in MELSEC iQ-F Series
- CVE-2024-1722 — Keycloak-core: dos via account lockout
Recently published
- CVE-2026-53982 — Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
- CVE-2026-25907 — Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unau
- CVE-2025-5241 — Denial-of-Service Vulnerability in MELSEC iQ-F Series
- CVE-2025-31947 — Repeated LDAP login failures can lock an LDAP account
- CVE-2024-37028 — BIG-IP Next Central Manager vulnerability
- CVE-2024-1722 — Keycloak-core: dos via account lockout