Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.
You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.