Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2026-77561MEDIUMTinyauth: Unauthenticated login attempts can trigger global login lockdown denial of serviceEPSS 0.5%CVE-2025-5864MEDIUMTenda TDSEE App Password Reset Confirmation Code ConfirmSmsCode excessive authenticationEPSS 0.5%CVE-2023-45149MEDIUMPassword of talk conversations can be bruteforced in NextcloudEPSS 0.5%CVE-2023-34001MEDIUMWordPress Hide My WP Ghost – Security Plugin plugin <= 5.0.25 - Captcha Bypass vulnerabilityEPSS 0.5%CVE-2026-20792HIGHChargemap chargemap.com Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2025-66204MEDIUMWBCE CMS allows brute-force protection bypass using X-Forwarded-For headerEPSS 0.5%CVE-2023-26271MEDIUMIBM Security Guardium Data Encryption information disclosureEPSS 0.5%CVE-2026-25114HIGHCloudCharge cloudcharge.se Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2026-26305HIGHMobility46 mobility46.se Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2025-2171HIGHAviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversEPSS 0.5%CVE-2025-43863LOWvantage6 lacks brute-force protection on change password functionalityEPSS 0.5%CVE-2026-24436CRITICALTenda W30E V2 Lacks Rate Limiting on AuthenticationEPSS 0.5%CVE-2024-42465CRITICALLack of resources and rate limiting - two factor authenticationEPSS 0.5%CVE-2026-33640CRITICALOutline has a rate limit bypass that allows brute force of email login OTPEPSS 0.5%CVE-2024-32774MEDIUMWordPress ProfileGrid plugin <= 5.8.2 - Group Members Limit Bypass vulnerabilityEPSS 0.5%CVE-2026-25113HIGHSWITCH EV swtchenergy.com Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2025-7393CRITICALMail Login - Critical - Access bypass - SA-CONTRIB-2025-088EPSS 0.5%CVE-2022-26964HIGHWeak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-fEPSS 0.5%CVE-2024-0787MEDIUMImproper Restriction of Excessive Authentication Attempts in phpipam/phpipamEPSS 0.5%CVE-2024-5862HIGHUser Enumeration in Mia Technology's Mia-Med Health AplicationEPSS 0.5%