CWE-645Base1 in KEV

Overly Restrictive Account Lockout Mechanism

Incomplete in the CWE catalog · 7 CVEs mapped

7
CVEs mapped
1
In KEV
5.8
Median CVSS
What it is

The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.

Recent examples
7.1cvss
CVE-2026-53982

Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association

Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to be redirected to an account-disabled page for approximately 30 days, preventing any account login or registration from that device.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2026-25907

Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability

Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2025-5241

Denial-of-Service Vulnerability in MELSEC iQ-F Series

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain period by repeatedly attempting to login with incorrect passwords. The legitimate users will be unable to login until a certain period has passed after the lockout or until the product is reset.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-645
Abstraction
Base
Structure
Simple
Status
Incomplete