Common Weakness Enumeration

    CWE Definition / CWE-645

    CWE-645: Overly Restrictive Account Lockout Mechanism

    The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.

    Published:30 Jan 2008
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-287: Improper Authentication