Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2026-33935HIGHMyTube has Unauthenticated Account Lockout via Shared Login Attempt StateEPSS 0.5%CVE-2025-48187CRITICALRAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification cEPSS 0.5%CVE-2023-32657MEDIUMWeintek Weincloud Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2024-8462MEDIUMWindmill HTTP Request users.rs excessive authenticationEPSS 0.5%CVE-2025-3709CRITICALFlowring Technology Agentflow - Account Lockout BypassEPSS 0.5%CVE-2024-41904HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not prEPSS 0.5%CVE-2026-42952HIGHHydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2023-54347HIGHOpenEMR 7.0.1 Authentication Brute Force Mitigation BypassEPSS 0.5%CVE-2024-21500MEDIUMAll versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts vEPSS 0.5%CVE-2025-54833MEDIUMOPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypassEPSS 0.5%CVE-2022-42478HIGHAn Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access EPSS 0.5%CVE-2022-38491HIGHAn issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-fEPSS 0.5%CVE-2026-32292CRITICALGL-iNet Comet (GL-RM1) KVM insufficient login rate-limitingEPSS 0.5%CVE-2026-75773MEDIUMkarakeep-app karakeep Login Endpoint auth.ts authorize excessive authenticationEPSS 0.5%CVE-2023-45582MEDIUMAn improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0EPSS 0.5%CVE-2025-52997MEDIUMFile Browser Insecurely Handles PasswordsEPSS 0.5%CVE-2026-25945HIGHEV2GO ev2go.io Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2024-28825MEDIUMBrute-force protection ineffective for some login methodsEPSS 0.5%CVE-2026-62220MEDIUMOpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit BypassEPSS 0.5%CVE-2025-49195MEDIUMNo protection against brute-force attacksEPSS 0.5%