CWE-645: Overly Restrictive Account Lockout Mechanism
low-riskThe product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.
Abstraction: Base
Common Consequences
Availability
→
DoS: Resource Consumption (Other)
Real-World Examples (6)
| CVE | CVSS | EPSS | KEV |
|---|---|---|---|
| CVE-2024-1722 | 3.7 | 0.4% | — |
| CVE-2025-31947 | 5.8 | 0.4% | — |
| CVE-2024-37028 | 5.3 | 0.3% | — |
| CVE-2025-5241 | 5.3 | 0.2% | — |
| CVE-2026-25907 | 5.3 | 0.1% | — |
| CVE-2023-4346 | 7.5 | 0.0% | — |
0
/ 100
low-risk
Active Threat
0/50 · Minimal
Exploit Availability
0/50 · Minimal